[Secure-testing-commits] r39274 - in data: . CVE

Guido Guenther agx at moszumanska.debian.org
Thu Jan 28 20:22:23 UTC 2016


Author: agx
Date: 2016-01-28 20:22:23 +0000 (Thu, 28 Jan 2016)
New Revision: 39274

Modified:
   data/CVE/list
   data/dla-needed.txt
Log:
chrony in squeeze affected by CVE-2016-1567

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-01-28 20:02:57 UTC (rev 39273)
+++ data/CVE/list	2016-01-28 20:22:23 UTC (rev 39274)
@@ -1389,6 +1389,8 @@
 	- chrony <unfixed> (bug #812923)
 	NOTE: http://www.talosintel.com/reports/TALOS-2016-0071/
 	NOTE: http://chrony.tuxfamily.org/news.html#_20_jan_2016_chrony_2_2_1_and_chrony_1_31_2_released
+	NOTE: Fix for 2.x http://git.tuxfamily.org/chrony/chrony.git/commit/?id=a78bf9725a7b481ebff0e0c321294ba767f2c1d8
+	NOTE: Fix for 1.x http://git.tuxfamily.org/chrony/chrony.git/commit/?h=1.31-security&id=df46e5ca5d70be1c0ae037f96b4b038362703832
 CVE-2016-1566
 	RESERVED
 CVE-2016-1565 (Cross-site scripting (XSS) vulnerability in the Field Group module ...)

Modified: data/dla-needed.txt
===================================================================
--- data/dla-needed.txt	2016-01-28 20:02:57 UTC (rev 39273)
+++ data/dla-needed.txt	2016-01-28 20:22:23 UTC (rev 39274)
@@ -14,6 +14,8 @@
 cakephp
   NOTE: 20160123, No official solution is currently available.
 --
+chrony
+--
 cpio
   NOTE: 20160123, no fix available yet
 --




More information about the Secure-testing-commits mailing list