[Secure-testing-commits] r43885 - data/CVE

Bastian Blank waldi at moszumanska.debian.org
Tue Aug 9 08:11:00 UTC 2016


Author: waldi
Date: 2016-08-09 08:11:00 +0000 (Tue, 09 Aug 2016)
New Revision: 43885

Modified:
   data/CVE/list
Log:
Mark CVE-2016-4962 and CVE-2016-5403 as no-dsa for wheezy


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-08-09 07:50:54 UTC (rev 43884)
+++ data/CVE/list	2016-08-09 08:11:00 UTC (rev 43885)
@@ -3829,6 +3829,7 @@
 	[jessie] - qemu <no-dsa> (Minor issue; can be fixed in future DSA or point release)
 	- qemu-kvm <removed>
 	- xen 4.4.0-1
+	[wheezy] - xen <no-dsa> (Minor issue)
 	NOTE: Xen switched to qemu-system in 4.4.0-1
 CVE-2016-5402
 	RESERVED
@@ -5765,6 +5766,7 @@
 CVE-2016-4962 (The libxl device-handling in Xen 4.6.x and earlier allows local OS ...)
 	{DSA-3633-1}
 	- xen <unfixed>
+	[wheezy] - xen <no-dsa> (Too intrusive to backport, libvirt doesn't have libxl driver enabled)
 	NOTE: http://xenbits.xen.org/xsa/advisory-175.html
 CVE-2016-4961
 	RESERVED




More information about the Secure-testing-commits mailing list