Author: joeyh Date: 2011-03-24 09:15:18 +0000 (Thu, 24 Mar 2011) New Revision: 16428 Modified: data/CVE/list Log: automatic update Modified: data/CVE/list ==================================================================--- data/CVE/list 2011-03-24 08:58:00 UTC (rev 16427) +++ data/CVE/list 2011-03-24 09:15:18 UTC (rev 16428) @@ -811,6 +811,7 @@ RESERVED CVE-2011-1176 [apache2-mpm-itk config misparsing] RESERVED + {DSA-2202-1} - apache2 2.2.17-2 (bug #618857; medium) [lenny] - apache2 <not-affected> (different source package in lenny: apache2-mpm-itk) [lenny] - apache2-mpm-itk <not-affected> (bug was introduced later, in 2.2.11-01) @@ -913,10 +914,13 @@ CVE-2011-1142 (Stack consumption vulnerability in the dissect_ber_choice function in ...) - wireshark 1.4.4-1 (unimportant) CVE-2011-1141 (epan/dissectors/packet-ldap.c in Wireshark 1.0.x, 1.2.0 through ...) + {DSA-2201-1} - wireshark 1.4.4-1 (unimportant) CVE-2011-1140 (Multiple stack consumption vulnerabilities in the ...) + {DSA-2201-1} - wireshark 1.4.4-1 (unimportant) CVE-2011-1139 (wiretap/pcapng.c in Wireshark 1.2.0 through 1.2.14 and 1.4.0 through ...) + {DSA-2201-1} - wireshark 1.4.4-1 (unimportant) CVE-2011-1138 (Off-by-one error in the dissect_6lowpan_iphc function in ...) - wireshark 1.4.4-1 @@ -2167,6 +2171,7 @@ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=678144 NOTE: http://seclists.org/oss-sec/2011/q1/438 CVE-2011-0713 (Heap-based buffer overflow in wiretap/dct3trace.c in Wireshark 1.2.0 ...) + {DSA-2201-1} - wireshark 1.4.4-1 [lenny] - wireshark <not-affected> (Vulnerable code not present) NOTE: http://anonsvn.wireshark.org/viewvc?view=rev&revision=35953 @@ -2612,6 +2617,7 @@ [wheezy] - openssh <not-affected> (only affects openssh 5.6 and 5.7) TODO: remove wheezy not-affected note once newer version transitions CVE-2011-0538 (Wireshark 1.2.0 through 1.2.14, 1.4.0 through 1.4.3, and 1.5.0 frees ...) + {DSA-2201-1} - wireshark 1.4.3-3 (low; bug #613202) CVE-2011-0537 (Multiple directory traversal vulnerabilities in (1) ...) - mediawiki <not-affected> (Only affected when running on Windows or Novell Netware)