[Secure-testing-commits] r43536 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Wed Jul 27 15:54:27 UTC 2016


Author: carnil
Date: 2016-07-27 15:54:27 +0000 (Wed, 27 Jul 2016)
New Revision: 43536

Modified:
   data/CVE/list
Log:
Mark CVE-2016-6349 as unimportant

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-07-27 15:40:25 UTC (rev 43535)
+++ data/CVE/list	2016-07-27 15:54:27 UTC (rev 43536)
@@ -14,8 +14,13 @@
 CVE-2016-6350
 	NOT-FOR-US: OpenBSD
 CVE-2016-6349 [information exposure for docker containers]
-	- systemd <unfixed>
+	- systemd <unfixed> (unimportant)
 	NOTE: http://www.openwall.com/lists/oss-security/2016/07/26/5
+	NOTE: Requirement is that docker containers would register themselves to
+	NOTE: to systemd-machined by oci-register-machine (not packaged in Debian,
+	NOTE: and https://github.com/projectatomic/docker/commit/a307e90141ba31b378bc31bb7720ed141f47cd9b
+	NOTE: not applied to docker.io).
+	NOTE: https://github.com/systemd/systemd/issues/3815
 CVE-2016-6287
 	RESERVED
 CVE-2016-6286




More information about the Secure-testing-commits mailing list