[Secure-testing-commits] r53285 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sat Jul 8 13:20:07 UTC 2017


Author: carnil
Date: 2017-07-08 13:20:07 +0000 (Sat, 08 Jul 2017)
New Revision: 53285

Modified:
   data/CVE/list
Log:
Add CVE-2017-7660/lucene-solr

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-07-08 12:49:28 UTC (rev 53284)
+++ data/CVE/list	2017-07-08 13:20:07 UTC (rev 53285)
@@ -9191,7 +9191,9 @@
 CVE-2017-7661 (Apache CXF Fediz ships with a number of container-specific plugins to ...)
 	NOT-FOR-US: Apache CXF
 CVE-2017-7660 (Apache Solr uses a PKI based mechanism to secure inter-node ...)
-	TODO: check
+	- lucene-solr <not-affected> (Vulnerable code introduced later)
+	NOTE: https://issues.apache.org/jira/browse/SOLR-10624
+	NOTE: http://git-wip-us.apache.org/repos/asf/lucene-solr/commit/2f5ecbcf
 CVE-2017-7659 [mod_http2 null pointer dereference]
 	RESERVED
 	- apache2 2.4.25-4




More information about the Secure-testing-commits mailing list