[Secure-testing-commits] r49536 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Mar 9 15:10:26 UTC 2017


Author: carnil
Date: 2017-03-09 15:10:26 +0000 (Thu, 09 Mar 2017)
New Revision: 49536

Modified:
   data/CVE/list
Log:
Update information for CVE-2017-2590/freeipa

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-03-09 10:27:41 UTC (rev 49535)
+++ data/CVE/list	2017-03-09 15:10:26 UTC (rev 49536)
@@ -11208,10 +11208,12 @@
 	- 389-ds-base 1.3.5.15-2 (bug #851769)
 	[jessie] - 389-ds-base <not-affected> (Only affects 1.3.4.0 and later)
 	NOTE: https://fedorahosted.org/389/changeset/ffda694dd622b31277da07be76d3469fad86150f/
-CVE-2017-2590
+CVE-2017-2590 [Insufficient permission check for ca-del, ca-disable and ca-enable commands]
 	RESERVED
-	- freeipa <unfixed>
+	- freeipa <not-affected> (ca plugin introduced in 4.4)
 	NOTE: https://pagure.io/freeipa/issue/6713
+	NOTE: Fixed by (master): https://pagure.io/freeipa/c/b81ac59640f0b76fa9f53cf8be441f085a7089c4?branch=master
+	NOTE: Fixed by (ipa-4.4): https://pagure.io/freeipa/c/1aa314c79648c442473f19344387bfe11ec2141b?branch=ipa-4-4
 CVE-2017-2589
 	RESERVED
 CVE-2017-2588




More information about the Secure-testing-commits mailing list