[Secure-testing-commits] r36462 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Fri Sep 4 04:44:12 UTC 2015


Author: carnil
Date: 2015-09-04 04:44:12 +0000 (Fri, 04 Sep 2015)
New Revision: 36462

Modified:
   data/CVE/list
Log:
Better comment/clarification for the 2.0-2 fix

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-09-04 04:44:05 UTC (rev 36461)
+++ data/CVE/list	2015-09-04 04:44:12 UTC (rev 36462)
@@ -1,7 +1,7 @@
 CVE-2015-XXXX [val_dane_check: usage DANE-TA(2) may bypass cert validation entirely]
 	[experimental] - dnsval 2.1-1
 	- dnsval 2.0-2 (bug #797470)
-	NOTE: dnsval/2.0-2 only disables usage 2 because not implemented correctly
+	NOTE: dnsval/2.0-2 only disables/let val_dane_check fail on usage 2 because not implemented correctly
 CVE-2015-XXXX [Memory corruption]
 	- libvncserver 0.9.8-1
 	NOTE: https://github.com/LibVNC/libvncserver/commit/804335f9d296440bb708ca844f5d89b58b50b0c6




More information about the Secure-testing-commits mailing list