[Secure-testing-commits] r41383 - data/CVE
Salvatore Bonaccorso
carnil at moszumanska.debian.org
Tue May 3 15:35:08 UTC 2016
Author: carnil
Date: 2016-05-03 15:35:07 +0000 (Tue, 03 May 2016)
New Revision: 41383
Modified:
data/CVE/list
Log:
Update information for atheme-services issues
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2016-05-03 15:30:48 UTC (rev 41382)
+++ data/CVE/list 2016-05-03 15:35:07 UTC (rev 41383)
@@ -124,15 +124,15 @@
RESERVED
CVE-2014-9773 [A remote attacker could change Atheme's behavior by registering/dropping certain accounts/nicks]
- atheme-services <unfixed>
+ [jessie] - atheme-services <not-affected> (Vulnerable code introduced later)
NOTE: https://github.com/atheme/atheme/issues/397
- NOTE: https://github.com/atheme/atheme/commit/c597156adc60a45b5f827793cd420945f47bc03b
+ NOTE: Fixed by: https://github.com/atheme/atheme/commit/c597156adc60a45b5f827793cd420945f47bc03b
+ NOTE: Introduced in: https://github.com/atheme/atheme/commit/5c734f28068cf47b9b450af4dcf37195734b15be
NOTE: http://www.openwall.com/lists/oss-security/2016/05/02/2
- TODO: check
CVE-2016-4478 [denial of service due to a buffer overflow in the XMLRPC response encoding code]
- atheme-services <unfixed>
NOTE: https://github.com/atheme/atheme/commit/87580d767868360d2fed503980129504da84b63e
NOTE: http://www.openwall.com/lists/oss-security/2016/05/02/2
- TODO: check
CVE-2016-4425 [stack exhaustion parsing a JSON file]
- jansson <unfixed> (bug #823238)
NOTE: https://github.com/akheron/jansson/issues/282
More information about the Secure-testing-commits
mailing list