[Secure-testing-commits] r56947 - data/CVE

Moritz Muehlenhoff jmm at moszumanska.debian.org
Tue Oct 24 20:37:30 UTC 2017


Author: jmm
Date: 2017-10-24 20:37:30 +0000 (Tue, 24 Oct 2017)
New Revision: 56947

Modified:
   data/CVE/list
Log:
fix source package for CVE-2017-12618, filed bug


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-10-24 20:33:01 UTC (rev 56946)
+++ data/CVE/list	2017-10-24 20:37:30 UTC (rev 56947)
@@ -9065,8 +9065,7 @@
 CVE-2017-12619
 	RESERVED
 CVE-2017-12618 (Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to ...)
-	- apr <unfixed>
-	TODO: check
+	- apr-util <unfixed> (low; bug #879708)
 CVE-2017-12617 (When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to ...)
 	- tomcat9 <itp> (bug #802312)
 	- tomcat8 <unfixed>
@@ -9092,8 +9091,7 @@
 CVE-2017-12614
 	RESERVED
 CVE-2017-12613 (When apr_exp_time*() or apr_os_exp_time*() functions are invoked with ...)
-	- apr <unfixed>
-	TODO: check
+	- apr <unfixed> (low; bug #879708)
 CVE-2017-12612 (In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe ...)
 	NOT-FOR-US: Apache Spark
 CVE-2017-12611 (In Apache Struts 2.0.1 through 2.3.33 and 2.5 through 2.5.10, using an ...)




More information about the Secure-testing-commits mailing list