[Secure-testing-commits] r57063 - data/CVE

Moritz Muehlenhoff jmm at moszumanska.debian.org
Sat Oct 28 10:00:01 UTC 2017


Author: jmm
Date: 2017-10-28 10:00:01 +0000 (Sat, 28 Oct 2017)
New Revision: 57063

Modified:
   data/CVE/list
Log:
new ruby-ox issue
NFUs


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-10-28 09:57:13 UTC (rev 57062)
+++ data/CVE/list	2017-10-28 10:00:01 UTC (rev 57063)
@@ -36,15 +36,15 @@
 	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=1b86808a86077722ee4f42ff97f836b12420bb2a
  	NOTE: https://blogs.gentoo.org/ago/2017/10/24/binutils-invalid-memory-read-in-find_abstract_instance_name-dwarf2-c/
 CVE-2017-15937 (Artica Pandora FMS version 7.0 leaks a full installation pathname via ...)
-	TODO: check
+	NOT-FOR-US: Artica Pandora FMS
 CVE-2017-15936 (In Artica Pandora FMS version 7.0, an Attacker with write Permission ...)
-	TODO: check
+	NOT-FOR-US: Artica Pandora FMS
 CVE-2017-15935 (Artica Pandora FMS version 7.0 is vulnerable to remote PHP code ...)
-	TODO: check
+	NOT-FOR-US: Artica Pandora FMS
 CVE-2017-15934 (Artica Pandora FMS version 7.0 is vulnerable to stored Cross-Site ...)
-	TODO: check
+	NOT-FOR-US: Artica Pandora FMS
 CVE-2017-15933 (SQL injection vulnerability vulnerability in the EyesOfNetwork web ...)
-	TODO: check
+	NOT-FOR-US: EyesOfNetwork (EON)
 CVE-2017-15932 (In radare2 2.0.1, an integer exception (negative number leading to an ...)
 	- radare2 <unfixed>
 	NOTE: https://github.com/radare/radare2/commit/44ded3ff35b8264f54b5a900cab32ec489d9e5b9
@@ -64,7 +64,9 @@
 CVE-2017-15929
 	RESERVED
 CVE-2017-15928 (In the Ox gem 2.8.0 for Ruby, the process crashes with a segmentation ...)
-	TODO: check
+	- ruby-ox <unfixed>
+	NOTE: https://github.com/ohler55/ox/issues/194
+	NOTE: https://rubygems.org/gems/ox/versions/2.8.0
 CVE-2017-15927
 	RESERVED
 CVE-2017-15926




More information about the Secure-testing-commits mailing list