[Secure-testing-commits] r39466 - in data: . CVE DSA
Salvatore Bonaccorso
carnil at moszumanska.debian.org
Thu Feb 4 20:31:58 UTC 2016
Author: carnil
Date: 2016-02-04 20:31:58 +0000 (Thu, 04 Feb 2016)
New Revision: 39466
Modified:
data/CVE/list
data/DSA/list
data/dsa-needed.txt
Log:
Reserve DSA number for krb5
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2016-02-04 19:30:50 UTC (rev 39465)
+++ data/CVE/list 2016-02-04 20:31:58 UTC (rev 39466)
@@ -3303,6 +3303,7 @@
CVE-2015-8630 [krb5 doesn't check for null policy when KADM5_POLICY is set in the mask]
RESERVED
- krb5 <unfixed> (bug #813127)
+ [jessie] - krb5 1.12.1+dfsg-19+deb8u2
[wheezy] - krb5 <not-affected> (Vulnerability introduced in 1.12)
[squeeze] - krb5 <not-affected> (Vulnerability introduced in 1.12)
NOTE: Fixed by: https://github.com/krb5/krb5/commit/b863de7fbf080b15e347a736fdda0a82d42f4f6b
Modified: data/DSA/list
===================================================================
--- data/DSA/list 2016-02-04 19:30:50 UTC (rev 39465)
+++ data/DSA/list 2016-02-04 20:31:58 UTC (rev 39466)
@@ -1,3 +1,7 @@
+[04 Feb 2016] DSA-3466-1 krb5 - security update
+ {CVE-2015-8629 CVE-2015-8631}
+ [wheezy] - krb5 1.10.1+dfsg-5+deb7u7
+ [jessie] - krb5 1.12.1+dfsg-19+deb8u2
[02 Feb 2016] DSA-3465-1 openjdk-6 - security update
{CVE-2015-7575 CVE-2016-0402 CVE-2016-0448 CVE-2016-0466 CVE-2016-0483 CVE-2016-0494 CVE-2015-4734 CVE-2015-4803 CVE-2015-4805 CVE-2015-4806 CVE-2015-4835 CVE-2015-4842 CVE-2015-4843 CVE-2015-4844 CVE-2015-4860 CVE-2015-4872 CVE-2015-4881 CVE-2015-4882 CVE-2015-4883 CVE-2015-4893 CVE-2015-4903 CVE-2015-4911}
[wheezy] - openjdk-6 6b38-1.13.10-1~deb7u1
Modified: data/dsa-needed.txt
===================================================================
--- data/dsa-needed.txt 2016-02-04 19:30:50 UTC (rev 39465)
+++ data/dsa-needed.txt 2016-02-04 20:31:58 UTC (rev 39466)
@@ -28,10 +28,6 @@
no-dsa bugs CVE-2014-8354 CVE-2014-8355 CVE-2014-8562 CVE-2014-8716
should be fixed along
--
-krb5
- Update for jessie-securiy ready (carnil)
- Packages for testing: https://people.debian.org/~carnil/tmp/krb5/
---
libav/oldstable
--
libidn
More information about the Secure-testing-commits
mailing list