[Secure-testing-commits] r56348 - data/CVE

Moritz Muehlenhoff jmm at moszumanska.debian.org
Mon Oct 2 13:14:23 UTC 2017


Author: jmm
Date: 2017-10-02 13:14:23 +0000 (Mon, 02 Oct 2017)
New Revision: 56348

Modified:
   data/CVE/list
Log:
openldap unimportant
arc ignored


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-10-02 12:05:51 UTC (rev 56347)
+++ data/CVE/list	2017-10-02 13:14:23 UTC (rev 56348)
@@ -2211,11 +2211,9 @@
 	- bzr 2.7.0+bzr6622-7 (bug #874429)
 	NOTE: https://bugs.launchpad.net/bzr/+bug/1710979
 CVE-2017-14159 (slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping ...)
-	- openldap <unfixed>
-	[stretch] - openldap <no-dsa> (Minor issue)
-	[jessie] - openldap <no-dsa> (Minor issue)
-	[wheezy] - openldap <no-dsa> (Minor issue)
+	- openldap <unfixed> (unimportant)
 	NOTE: http://www.openldap.org/its/index.cgi?findid=8703
+	NOTE: Negligable security impact, but filed #877512
 CVE-2017-14158 (Scrapy 1.4 allows remote attackers to cause a denial of service (memory ...)
 	- python-scrapy <unfixed> (bug #875947)
 	[stretch] - python-scrapy <no-dsa> (Minor issue)
@@ -98226,8 +98224,8 @@
 	NOTE: CVE Request: https://marc.info/?l=oss-security&m=142024361327375&w=2
 CVE-2015-XXXX [buffer over-read]
 	- arc <unfixed> (low; bug #774439)
-	[stretch] - arc <no-dsa> (Minor issue)
-	[jessie] - arc <no-dsa> (Minor issue)
+	[stretch] - arc <ignored> (Minor issue)
+	[jessie] - arc <ignored> (Minor issue)
 	[wheezy] - arc <no-dsa> (Minor issue)
 	[squeeze] - arc <no-dsa> (Minor issue)
 CVE-2015-0557 (Open-source ARJ archiver 3.10.22 does not properly remove leading ...)




More information about the Secure-testing-commits mailing list