[Secure-testing-commits] r36610 - in data: . CVE

Guido Guenther agx at moszumanska.debian.org
Fri Sep 11 13:20:13 UTC 2015


Author: agx
Date: 2015-09-11 13:20:13 +0000 (Fri, 11 Sep 2015)
New Revision: 36610

Modified:
   data/CVE/list
   data/dla-needed.txt
Log:
Add commons-httpclient to dla-needed and add bugnumber

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-09-11 13:06:35 UTC (rev 36609)
+++ data/CVE/list	2015-09-11 13:20:13 UTC (rev 36610)
@@ -3908,7 +3908,7 @@
 CVE-2015-5262
 	RESERVED
 	- httpcomponents-client <unfixed>
-	- commons-httpclient <unfixed>
+	- commons-httpclient <unfixed> (bug #798650)
 	TODO: check
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1261538
 	NOTE: https://issues.apache.org/jira/browse/HTTPCLIENT-1478

Modified: data/dla-needed.txt
===================================================================
--- data/dla-needed.txt	2015-09-11 13:06:35 UTC (rev 36609)
+++ data/dla-needed.txt	2015-09-11 13:20:13 UTC (rev 36610)
@@ -9,6 +9,9 @@
 --
 binutils (Ben Hutchings)
 --
+commons-httpclient
+  NOTE: there a three no-dsa issues open as well (CVE-2014-3577, CVE-2012-6153, CVE-2012-5783)
+--
 cups
 --
 flightgear




More information about the Secure-testing-commits mailing list