[Secure-testing-commits] r52842 - data/CVE

Guido Guenther agx at moszumanska.debian.org
Fri Jun 23 11:05:06 UTC 2017


Author: agx
Date: 2017-06-23 11:05:06 +0000 (Fri, 23 Jun 2017)
New Revision: 52842

Modified:
   data/CVE/list
Log:
lts: mark issues for code introduced post wheezy in qemu-kvm as not-affected

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-06-23 11:04:56 UTC (rev 52841)
+++ data/CVE/list	2017-06-23 11:05:06 UTC (rev 52842)
@@ -2051,7 +2051,9 @@
 CVE-2017-9524 [nbd: segmentation fault due to client non-negotiation]
 	RESERVED
 	- qemu <unfixed>
+	[wheezy] - qemu <not-affected> (Vulnerable code not present)
 	- qemu-kvm <removed>
+	[wheezy] - emu-kvm <not-affected> (Vulnerable code not present)
 	NOTE: https://lists.gnu.org/archive/html/qemu-devel/2017-05/msg06240.html
 	NOTE: https://lists.gnu.org/archive/html/qemu-devel/2017-06/msg02321.html
 CVE-2017-9525 (In the cron package through 3.0pl1-128 on Debian, and through ...)
@@ -2107,7 +2109,9 @@
 	RESERVED
 CVE-2017-9503 (QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host ...)
 	- qemu <unfixed>
+	[wheezy] - qemu <not-affected> (Vulnerable code not present)
 	- qemu-kvm <removed>
+	[wheezy] - qemu-kvm <not-affected> (Vulnerable code not present)
 	NOTE: https://lists.gnu.org/archive/html/qemu-devel/2017-06/msg01313.html
 	NOTE: https://lists.gnu.org/archive/html/qemu-devel/2017-06/msg01309.html
 CVE-2017-9502 (In curl before 7.54.1 on Windows and DOS, libcurl's default protocol ...)




More information about the Secure-testing-commits mailing list