[Secure-testing-commits] r38669 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sun Jan 3 14:48:26 UTC 2016


Author: carnil
Date: 2016-01-03 14:48:25 +0000 (Sun, 03 Jan 2016)
New Revision: 38669

Modified:
   data/CVE/list
Log:
Mark busybox as no-dsa, left out squeeze-lts since it is listed in dla-needed.txt

Reasoning: Possibly only limited usecases where tar from busybox is
used.

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-01-03 14:37:31 UTC (rev 38668)
+++ data/CVE/list	2016-01-03 14:48:25 UTC (rev 38669)
@@ -11758,6 +11758,8 @@
 CVE-2011-5325 [Directory traversal via crafted tar file which contains a symlink pointing outside of the current directory]
 	RESERVED
 	- busybox <unfixed> (bug #802702)
+	[jessie] - busybox <no-dsa> (Minor issue)
+	[wheezy] - busybox <no-dsa> (Minor issue)
 CVE-2011-5324 (The TeraRecon server, as used in GE Healthcare Centricity PACS-IW ...)
 	NOT-FOR-US: GE Healthcare Centricity PACS-IW
 CVE-2011-5323 (GE Healthcare Centricity PACS-IW 3.7.3.7, 3.7.3.8, and possibly other ...)




More information about the Secure-testing-commits mailing list