[Secure-testing-commits] r39466 - in data: . CVE DSA

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Feb 4 20:31:58 UTC 2016


Author: carnil
Date: 2016-02-04 20:31:58 +0000 (Thu, 04 Feb 2016)
New Revision: 39466

Modified:
   data/CVE/list
   data/DSA/list
   data/dsa-needed.txt
Log:
Reserve DSA number for krb5

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-02-04 19:30:50 UTC (rev 39465)
+++ data/CVE/list	2016-02-04 20:31:58 UTC (rev 39466)
@@ -3303,6 +3303,7 @@
 CVE-2015-8630 [krb5 doesn't check for null policy when KADM5_POLICY is set in the mask]
 	RESERVED
 	- krb5 <unfixed> (bug #813127)
+	[jessie] - krb5 1.12.1+dfsg-19+deb8u2
 	[wheezy] - krb5 <not-affected> (Vulnerability introduced in 1.12)
 	[squeeze] - krb5 <not-affected> (Vulnerability introduced in 1.12)
 	NOTE: Fixed by: https://github.com/krb5/krb5/commit/b863de7fbf080b15e347a736fdda0a82d42f4f6b

Modified: data/DSA/list
===================================================================
--- data/DSA/list	2016-02-04 19:30:50 UTC (rev 39465)
+++ data/DSA/list	2016-02-04 20:31:58 UTC (rev 39466)
@@ -1,3 +1,7 @@
+[04 Feb 2016] DSA-3466-1 krb5 - security update
+	{CVE-2015-8629 CVE-2015-8631}
+	[wheezy] - krb5 1.10.1+dfsg-5+deb7u7
+	[jessie] - krb5 1.12.1+dfsg-19+deb8u2
 [02 Feb 2016] DSA-3465-1 openjdk-6 - security update
 	{CVE-2015-7575 CVE-2016-0402 CVE-2016-0448 CVE-2016-0466 CVE-2016-0483 CVE-2016-0494 CVE-2015-4734 CVE-2015-4803 CVE-2015-4805 CVE-2015-4806 CVE-2015-4835 CVE-2015-4842 CVE-2015-4843 CVE-2015-4844 CVE-2015-4860 CVE-2015-4872 CVE-2015-4881 CVE-2015-4882 CVE-2015-4883 CVE-2015-4893 CVE-2015-4903 CVE-2015-4911}
 	[wheezy] - openjdk-6 6b38-1.13.10-1~deb7u1

Modified: data/dsa-needed.txt
===================================================================
--- data/dsa-needed.txt	2016-02-04 19:30:50 UTC (rev 39465)
+++ data/dsa-needed.txt	2016-02-04 20:31:58 UTC (rev 39466)
@@ -28,10 +28,6 @@
   no-dsa bugs CVE-2014-8354 CVE-2014-8355 CVE-2014-8562 CVE-2014-8716
   should be fixed along
 --
-krb5
-  Update for jessie-securiy ready (carnil)
-  Packages for testing: https://people.debian.org/~carnil/tmp/krb5/
---
 libav/oldstable
 --
 libidn




More information about the Secure-testing-commits mailing list