[Secure-testing-commits] r56785 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Tue Oct 17 17:01:46 UTC 2017


Author: carnil
Date: 2017-10-17 17:01:46 +0000 (Tue, 17 Oct 2017)
New Revision: 56785

Modified:
   data/CVE/list
Log:
Add details for CVE-2017-8805/archvsync

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-10-17 14:22:08 UTC (rev 56784)
+++ data/CVE/list	2017-10-17 17:01:46 UTC (rev 56785)
@@ -19148,9 +19148,11 @@
 	RESERVED
 CVE-2017-8806
 	RESERVED
-CVE-2017-8805
+CVE-2017-8805 [Unsafe symlinks not filtered in Debian mirror script ftpsync]
 	RESERVED
 	- archvsync 20171017
+	NOTE: http://www.openwall.com/lists/oss-security/2017/10/17/2
+	NOTE: https://anonscm.debian.org/cgit/mirror/archvsync.git/commit/?id=d1ca2ab2210990b6dfb664cd6776a41b71c48016
 CVE-2017-1000041
 	REJECTED
 CVE-2017-1000040




More information about the Secure-testing-commits mailing list