[Secure-testing-commits] r50389 - in data: . CVE

Brian May bam at moszumanska.debian.org
Wed Apr 5 22:03:30 UTC 2017


Author: bam
Date: 2017-04-05 22:03:30 +0000 (Wed, 05 Apr 2017)
New Revision: 50389

Modified:
   data/CVE/list
   data/dla-needed.txt
Log:
Claim XBMC and link to my findings

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-04-05 21:10:14 UTC (rev 50388)
+++ data/CVE/list	2017-04-05 22:03:30 UTC (rev 50389)
@@ -4113,6 +4113,7 @@
 	- xbmc <undetermined>
 	NOTE: http://seclists.org/fulldisclosure/2017/Feb/27
 	NOTE: http://trac.kodi.tv/ticket/17314
+	NOTE: https://lists.debian.org/debian-lts/2017/04/msg00025.html
 CVE-2017-5681 (The RSA-CRT implementation in the Intel QuickAssist Technology (QAT) ...)
 	NOT-FOR-US: Intel QuickAssist Technology (QAT) Engine
 CVE-2017-6056 (It was discovered that a programming error in the processing of HTTPS ...)

Modified: data/dla-needed.txt
===================================================================
--- data/dla-needed.txt	2017-04-05 21:10:14 UTC (rev 50388)
+++ data/dla-needed.txt	2017-04-05 22:03:30 UTC (rev 50389)
@@ -131,9 +131,8 @@
   NOTE: See email sent to debian-lts mailing list:
   NOTE: https://lists.debian.org/debian-lts/2017/03/msg00046.html
 --
-xbmc
-  NOTE: under reserve, could not reproduce with 2:12.3+dfsg1-3ubuntu1, which is newer than the Wheezy version
-  NOTE: no mail to maintainer yet
+xbmc (Brian May)
+  NOTE: Reproduced: https://lists.debian.org/debian-lts/2017/04/msg00025.html
 --
 xen
 --




More information about the Secure-testing-commits mailing list