[Secure-testing-commits] r40903 - data/CVE
Salvatore Bonaccorso
carnil at moszumanska.debian.org
Wed Apr 13 04:18:01 UTC 2016
Author: carnil
Date: 2016-04-13 04:18:01 +0000 (Wed, 13 Apr 2016)
New Revision: 40903
Modified:
data/CVE/list
Log:
Samba fixed in unstable
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2016-04-13 03:02:23 UTC (rev 40902)
+++ data/CVE/list 2016-04-13 04:18:01 UTC (rev 40903)
@@ -5229,7 +5229,7 @@
RESERVED
CVE-2016-2118 [SAMR and LSA man in the middle attacks possible]
RESERVED
- - samba <unfixed>
+ - samba 2:4.3.7+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2016-2118.html
NOTE: http://badlock.org/
CVE-2016-2117 [memory disclosure to ethernet due to unchecked scatter/gather IO]
@@ -5243,29 +5243,29 @@
NOTE: http://www.openwall.com/lists/oss-security/2016/03/03/12
CVE-2016-2115 [SMB client connections for IPC traffic are not integrity protected]
RESERVED
- - samba <unfixed>
+ - samba 2:4.3.7+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2016-2115.html
CVE-2016-2114 ["server signing = mandatory" not enforced]
RESERVED
- - samba <unfixed>
+ - samba 2:4.3.7+dfsg-1
[wheezy] - samba <not-affected> (Affects Samba 4.0.0 to 4.4.0)
NOTE: https://www.samba.org/samba/security/CVE-2016-2114.html
CVE-2016-2113 [Missing TLS certificate validation allows man in the middle attacks]
RESERVED
- - samba <unfixed>
+ - samba 2:4.3.7+dfsg-1
[wheezy] - samba <not-affected> (Affects Samba 4.0.0 to 4.4.0)
NOTE: https://www.samba.org/samba/security/CVE-2016-2113.html
CVE-2016-2112 [The LDAP client and server don't enforce integrity protection]
RESERVED
- - samba <unfixed>
+ - samba 2:4.3.7+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2016-2112.html
CVE-2016-2111 [NETLOGON Spoofing Vulnerability]
RESERVED
- - samba <unfixed>
+ - samba 2:4.3.7+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2016-2111.html
CVE-2016-2110 [an in the middle attacks possible with NTLMSSP]
RESERVED
- - samba <unfixed>
+ - samba 2:4.3.7+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2016-2110.html
CVE-2016-2109
RESERVED
@@ -20719,7 +20719,7 @@
NOT-FOR-US: SolarWinds
CVE-2015-5370 [Multiple errors in DCE-RPC code]
RESERVED
- - samba <unfixed>
+ - samba 2:4.3.7+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2015-5370.html
CVE-2015-5369 (Pulse Connect Secure (aka PCS and formerly Juniper PCS) PSC6000, ...)
NOT-FOR-US: Pulse Connect Secure / Juniper PCS
More information about the Secure-testing-commits
mailing list