[Secure-testing-commits] r44362 - in data: . CVE

Moritz Muehlenhoff jmm at moszumanska.debian.org
Tue Sep 6 09:21:11 UTC 2016


Author: jmm
Date: 2016-09-06 09:21:11 +0000 (Tue, 06 Sep 2016)
New Revision: 44362

Modified:
   data/CVE/list
   data/dsa-needed.txt
Log:
new curl issue
drop bogofilter from dsa-needed, needs further investigation


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-09-06 09:11:30 UTC (rev 44361)
+++ data/CVE/list	2016-09-06 09:21:11 UTC (rev 44362)
@@ -1,3 +1,7 @@
+CVE-2016-7141
+	- curl <unfixed> 
+	NOTE: Only affects libcurl3-nss
+	NOTE: http://seclists.org/oss-sec/2016/q3/419
 CVE-2016-7145 [certificate fingerprint spoofing through crafted SASL messages]
 	NOT-FOR-US: Nefarious 2
 CVE-2016-7144 [certificate fingerprint spoofing through crafted SASL messages]

Modified: data/dsa-needed.txt
===================================================================
--- data/dsa-needed.txt	2016-09-06 09:11:30 UTC (rev 44361)
+++ data/dsa-needed.txt	2016-09-06 09:21:11 UTC (rev 44362)
@@ -14,9 +14,6 @@
 --
 389-ds-base
 --
-bogofilter
-  Needs to have updated lexer_v3.c after the flex update
---
 graphicsmagick (luciano)
 --
 icu




More information about the Secure-testing-commits mailing list