[Secure-testing-commits] r53635 - data/CVE

Moritz Muehlenhoff jmm at moszumanska.debian.org
Tue Jul 18 21:58:30 UTC 2017


Author: jmm
Date: 2017-07-18 21:58:30 +0000 (Tue, 18 Jul 2017)
New Revision: 53635

Modified:
   data/CVE/list
Log:
DWF data quality has room for improvement... add duplicate for roundcube


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-07-18 21:49:53 UTC (rev 53634)
+++ data/CVE/list	2017-07-18 21:58:30 UTC (rev 53635)
@@ -810,9 +810,7 @@
 CVE-2017-1000051 (Cross-site scripting (XSS) vulnerability in pad export in XWiki labs ...)
 	NOT-FOR-US: XWiki labs
 CVE-2017-1000049 (Roundcube Webmail 1.1.5 is vulnerable to Persistent Xss ...)
-	- roundcube <undetermined>
-	NOTE: https://github.com/roundcube/roundcubemail/issues/4949
-	TODO: check if different from CVE-2015-2181
+	NOTE: Duplicate of CVE-2015-8864, requested rejection
 CVE-2017-1000048 (the web framework using ljharb's qs module older than v6.3.2, v6.2.3, ...)
 	NOT-FOR-US: ljharb
 CVE-2017-1000047 (rbenv (all current versions) is vulnerable to Directory Traversal in ...)




More information about the Secure-testing-commits mailing list