[Secure-testing-commits] r39684 - data/CVE

David Prévot taffit at moszumanska.debian.org
Sun Feb 14 19:37:41 UTC 2016


Author: taffit
Date: 2016-02-14 19:37:41 +0000 (Sun, 14 Feb 2016)
New Revision: 39684

Modified:
   data/CVE/list
Log:
Document CVE-2015-8371/composer

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-02-14 19:31:39 UTC (rev 39683)
+++ data/CVE/list	2016-02-14 19:37:41 UTC (rev 39684)
@@ -7276,8 +7276,9 @@
 	- isc-kea-dhcp-server <itp> (bug #759703)
 CVE-2015-8372
 	RESERVED
-CVE-2015-8371
-	RESERVED
+CVE-2015-8371 [Composer Cache Injection vulnerability]
+	- composer 1.0.0~alpha11-3
+	NOTE: http://flyingmana.de/blog_en/2016/02/14/composer_cache_injection_vulnerability_cve_2015_8371.html
 CVE-2015-8370 (Multiple integer underflows in Grub2 1.98 through 2.02 allow ...)
 	{DSA-3421-1 DLA-368-1}
 	- grub2 2.02~beta2-33 (bug #807614)




More information about the Secure-testing-commits mailing list