[Secure-testing-commits] r39590 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Wed Feb 10 18:49:52 UTC 2016


Author: carnil
Date: 2016-02-10 18:49:52 +0000 (Wed, 10 Feb 2016)
New Revision: 39590

Modified:
   data/CVE/list
Log:
Update information for CVE-2016-2313

Add bug reference to #814353 and add note about the issue not fixing a
real issue and possibly causing regression for some other users.

Cf. https://bugs.debian.org/814353#10

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-02-10 18:28:26 UTC (rev 39589)
+++ data/CVE/list	2016-02-10 18:49:52 UTC (rev 39590)
@@ -1,10 +1,11 @@
 CVE-2016-2313 [Authentication using web authentication as a user not in the cacti database allows complete access]
-	- cacti <unfixed>
+	- cacti <unfixed> (bug #814353)
 	NOTE: http://svn.cacti.net/viewvc/cacti/tags/0.8.8g/docs/CHANGELOG?revision=7788&view=markup
 	NOTE: http://bugs.cacti.net/view.php?id=2656
 	NOTE: Upstream fix: http://svn.cacti.net/viewvc?view=rev&revision=7770
 	NOTE: https://bugzilla.suse.com/show_bug.cgi?id=965930
 	NOTE: http://www.openwall.com/lists/oss-security/2016/02/09/3
+	NOTE: Issue might be disputed, see maintainers comment in https://bugs.debian.org/814353#10
 CVE-2016-2312 [KDE lockscreen bypass by switching display off and on]
 	- plasma-workspace <unfixed> (bug #814355)
 	NOTE: Affects plasma-workspace < 5.5.0, kscreenlocker < 5.5.5




More information about the Secure-testing-commits mailing list