[Secure-testing-commits] r40554 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Mar 24 16:15:25 UTC 2016


Author: carnil
Date: 2016-03-24 16:15:25 +0000 (Thu, 24 Mar 2016)
New Revision: 40554

Modified:
   data/CVE/list
Log:
Add CVE-2016-2166/qpid-proton

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-03-24 16:09:57 UTC (rev 40553)
+++ data/CVE/list	2016-03-24 16:15:25 UTC (rev 40554)
@@ -4042,8 +4042,12 @@
 	RESERVED
 CVE-2016-2167
 	RESERVED
-CVE-2016-2166
+CVE-2016-2166 [reactor sends messages in clear if ssl is requested but not available]
 	RESERVED
+	- qpid-proton <unfixed>
+	NOTE: https://issues.apache.org/jira/browse/PROTON-1157
+	NOTE: http://qpid.apache.org/releases/qpid-proton-0.12.1/
+	TODO: check
 CVE-2016-2165
 	RESERVED
 CVE-2016-2164




More information about the Secure-testing-commits mailing list