[Secure-testing-commits] r58148 - data/CVE
Salvatore Bonaccorso
carnil at moszumanska.debian.org
Thu Nov 30 17:55:14 UTC 2017
Author: carnil
Date: 2017-11-30 17:55:14 +0000 (Thu, 30 Nov 2017)
New Revision: 58148
Modified:
data/CVE/list
Log:
Slit up note over multiple lines
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2017-11-30 17:10:55 UTC (rev 58147)
+++ data/CVE/list 2017-11-30 17:55:14 UTC (rev 58148)
@@ -13858,11 +13858,14 @@
CVE-2017-12873 (SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain ...)
- simplesamlphp 1.14.15-1
NOTE: https://simplesamlphp.org/security/201612-04
- NOTE: Patches: https://github.com/simplesamlphp/simplesamlphp/commit/90dca835158495b173808273e7df127303b8b953aa https://github.com/simplesamlphp/simplesamlphp/commit/e2daf4ceb6e580815c3741384b3a09b85a5fc231 https://github.com/simplesamlphp/simplesamlphp/commit/300d8aa48fe93706ade95be481c68e9cf2f32d1f
+ NOTE: Patches: https://github.com/simplesamlphp/simplesamlphp/commit/90dca835158495b173808273e7df127303b8b953aa
+ NOTE: https://github.com/simplesamlphp/simplesamlphp/commit/e2daf4ceb6e580815c3741384b3a09b85a5fc231
+ NOTE: https://github.com/simplesamlphp/simplesamlphp/commit/300d8aa48fe93706ade95be481c68e9cf2f32d1f
CVE-2017-12872 (The (1) Htpasswd authentication source in the authcrypt module and (2) ...)
- simplesamlphp 1.14.15-1
NOTE: https://simplesamlphp.org/security/201703-01
- NOTE: Patch: https://github.com/simplesamlphp/simplesamlphp/commit/ab7761d4a523a4ed00479fb1ddba688e7ca72439 https://github.com/simplesamlphp/simplesamlphp/commit/caf764cc2c9b68ac29741070ebdf133a595443f1
+ NOTE: Patches: https://github.com/simplesamlphp/simplesamlphp/commit/ab7761d4a523a4ed00479fb1ddba688e7ca72439
+ NOTE: https://github.com/simplesamlphp/simplesamlphp/commit/caf764cc2c9b68ac29741070ebdf133a595443f1
CVE-2017-12871 (The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in ...)
- simplesamlphp 1.14.15-1
[jessie] - simplesamlphp <not-affected> (Vulnerable code not present)
More information about the Secure-testing-commits
mailing list