[Secure-testing-commits] r49130 - data/CVE

Moritz Muehlenhoff jmm at moszumanska.debian.org
Wed Feb 22 17:56:11 UTC 2017


Author: jmm
Date: 2017-02-22 17:56:08 +0000 (Wed, 22 Feb 2017)
New Revision: 49130

Modified:
   data/CVE/list
Log:
new cakephp issue


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-02-22 17:42:32 UTC (rev 49129)
+++ data/CVE/list	2017-02-22 17:56:08 UTC (rev 49130)
@@ -31564,7 +31564,7 @@
 CVE-2016-4846
 	RESERVED
 CVE-2016-4845 (Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE ...)
-	TODO: check
+	NOT-FOR-US: I-O DATA
 CVE-2016-4844
 	RESERVED
 CVE-2016-4843
@@ -31707,7 +31707,7 @@
 CVE-2016-4795
 	RESERVED
 CVE-2016-4793 (The clientIp function in CakePHP 3.2.4 and earlier allows remote ...)
-	TODO: check
+	- cakephp 2.8.3-1
 CVE-2016-4792 (Pulse Connect Secure (PCS) 8.2 before 8.2r1 allows remote attackers to ...)
 	NOT-FOR-US: Pulse Connect Secure
 CVE-2016-4791 (The administrative user interface in Pulse Connect Secure (PCS) 8.2 ...)




More information about the Secure-testing-commits mailing list