joeyh at alioth.debian.org
2008-May-13 21:14 UTC
[Secure-testing-commits] r8799 - data/CVE
Author: joeyh Date: 2008-05-13 21:14:14 +0000 (Tue, 13 May 2008) New Revision: 8799 Modified: data/CVE/list Log: automatic update Modified: data/CVE/list ==================================================================--- data/CVE/list 2008-05-13 17:04:26 UTC (rev 8798) +++ data/CVE/list 2008-05-13 21:14:14 UTC (rev 8799) @@ -4603,6 +4603,7 @@ RESERVED CVE-2008-0166 [openssl predictable random number generator] RESERVED + {DSA-1571-1} - openssl 0.9.8g-9 (high) [sarge] - openssl <not-affected> (Vulnerable code not present) NOTE: http://www.debian.org/security/key-rollover/ @@ -9998,6 +9999,7 @@ - pidgin 2.2.1-1 (medium) NOTE: Gaim not affected, vulnerable code was introduced in 2.2.0 CVE-2007-4995 (Off-by-one error in the DTLS implementation in OpenSSL 0.9.8 before ...) + {DSA-1571-1} - openssl 0.9.8f-1 (low) [etch] - openssl <no-dsa> (Will be fixed in a point update) TODO: [etch] - openssl 0.9.8c-4etch2 @@ -14571,6 +14573,7 @@ CVE-2007-3109 (The CERN Image Map Dispatcher (htimage.exe) in Microsoft FrontPage ...) NOT-FOR-US: Microsoft FrontPage CVE-2007-3108 (The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL ...) + {DSA-1571-1} - openssl 0.9.8e-6 (bug #438142; low) TODO: [etch] - openssl 0.9.8c-4etch2 - openssl097 <removed> (bug #438180)