[Secure-testing-commits] r39939 - data/CVE
Salvatore Bonaccorso
carnil at moszumanska.debian.org
Fri Feb 26 07:54:51 UTC 2016
Author: carnil
Date: 2016-02-26 07:54:51 +0000 (Fri, 26 Feb 2016)
New Revision: 39939
Modified:
data/CVE/list
Log:
Add new squid issues
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2016-02-26 07:49:00 UTC (rev 39938)
+++ data/CVE/list 2016-02-26 07:54:51 UTC (rev 39939)
@@ -1,6 +1,31 @@
CVE-2016-XXXX [out-of-bounds reads]
- cpio <unfixed> (bug #815965)
NOTE: CVE Request: http://www.openwall.com/lists/oss-security/2016/02/25/8
+CVE-2016-2572
+ - squid3 <not-affected> (Only affects 4.x)
+ - squid <not-affected> (Only affects 4.x)
+ NOTE: http://www.squid-cache.org/Advisories/SQUID-2016_2.txt
+ NOTE: http://www.squid-cache.org/Versions/v4/changesets/squid-4-14548.patch
+CVE-2016-2571
+ - squid3 <unfixed>
+ - squid <removed>
+ NOTE: http://www.squid-cache.org/Advisories/SQUID-2016_2.txt
+ NOTE: http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-13990.patch
+ NOTE: http://www.squid-cache.org/Versions/v4/changesets/squid-4-14548.patch
+ TODO: check versions
+CVE-2016-2570
+ - squid3 <unfixed>
+ - squid <removed>
+ NOTE: http://www.squid-cache.org/Advisories/SQUID-2016_2.txt
+ NOTE: http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-13993.patch
+ NOTE: http://www.squid-cache.org/Versions/v4/changesets/squid-4-14549.patch
+CVE-2016-2569
+ - squid3 <unfixed>
+ - squid <removed>
+ NOTE: http://www.squid-cache.org/Advisories/SQUID-2016_2.txt
+ NOTE: http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-13991.patch
+ NOTE: http://www.squid-cache.org/Versions/v4/changesets/squid-4-14552.patch
+ TODO: check versions
CVE-2016-2568 [Program run via pkexec as unprivileged user can escape to parent session via TIOCSTI ioctl]
- policykit-1 <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1300746
More information about the Secure-testing-commits
mailing list