joeyh at alioth.debian.org
2008-Oct-12 21:14 UTC
[Secure-testing-commits] r10066 - data/CVE
Author: joeyh
Date: 2008-10-12 21:14:13 +0000 (Sun, 12 Oct 2008)
New Revision: 10066
Modified:
data/CVE/list
Log:
automatic update
Modified: data/CVE/list
==================================================================---
data/CVE/list 2008-10-12 09:38:29 UTC (rev 10065)
+++ data/CVE/list 2008-10-12 21:14:13 UTC (rev 10066)
@@ -1431,6 +1431,7 @@
CVE-2008-3906 (CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier
allows ...)
- mono <unfixed> (low; bug #498894)
CVE-2008-3905 (resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287,
1.8.7 ...)
+ {DSA-1652-1 DSA-1651-1}
- ruby1.8 1.8.7.72-1 (bug #498978)
- ruby1.9 <unfixed> (bug #498977)
CVE-2008-3903 (Asterisk PBX 1.2 through 1.6 and Trixbox PBX 2.6.1, when running
with ...)
@@ -1843,6 +1844,7 @@
{DSA-1648-1}
- mon 0.99.2-13 (medium; bug #496398)
CVE-2008-3790 (The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through
...)
+ {DSA-1652-1 DSA-1651-1}
- ruby1.8 1.8.7.72-1 (bug #496808)
- ruby1.9 1.9.0.2-6 (bug #497610)
CVE-2008-XXXX [apertium: insecure temp files]
@@ -2194,14 +2196,17 @@
- php5 5.2.6-4 (medium)
NOTE: fix in pkg-php svn for both etch and sid
CVE-2008-3657 (The dl module in Ruby 1.8.5 and earlier, 1.8.6 through
1.8.6-p286, ...)
+ {DSA-1652-1 DSA-1651-1}
- ruby1.8 1.8.7.72-1 (bug #494401)
- ruby1.9 1.9.0.2-6 (bug #494402)
NOTE:
http://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby/
CVE-2008-3656 (Algorithmic complexity vulnerability in ...)
+ {DSA-1652-1 DSA-1651-1}
- ruby1.8 1.8.7.72-1 (bug #494401)
- ruby1.9 1.9.0.2-6 (bug #494402)
NOTE:
http://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby/
CVE-2008-3655 (Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through
...)
+ {DSA-1652-1 DSA-1651-1}
- ruby1.8 1.8.7.72-1 (bug #494401)
- ruby1.9 1.9.0.2-6 (bug #494402)
NOTE:
http://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby/
@@ -4027,7 +4032,7 @@
- wireshark 1.0.1-1 (low; bug #488834)
NOTE: http://www.wireshark.org/security/wnpa-sec-2008-03.html
CVE-2008-2952 (liblber/io.c in OpenLDAP 2.2.4 to 2.4.10 allows remote attackers
to ...)
- {DTSA-151-1}
+ {DSA-1650-1 DTSA-151-1}
- openldap2.3 <removed> (low; bug #488710)
- openldap 2.4.10-3 (low; bug #488710)
CVE-2008-2955 (Pidgin 2.4.1 allows remote attackers to cause a denial of
service ...)