joeyh at alioth.debian.org
2008-Oct-12 21:14 UTC
[Secure-testing-commits] r10066 - data/CVE
Author: joeyh Date: 2008-10-12 21:14:13 +0000 (Sun, 12 Oct 2008) New Revision: 10066 Modified: data/CVE/list Log: automatic update Modified: data/CVE/list ==================================================================--- data/CVE/list 2008-10-12 09:38:29 UTC (rev 10065) +++ data/CVE/list 2008-10-12 21:14:13 UTC (rev 10066) @@ -1431,6 +1431,7 @@ CVE-2008-3906 (CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows ...) - mono <unfixed> (low; bug #498894) CVE-2008-3905 (resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 ...) + {DSA-1652-1 DSA-1651-1} - ruby1.8 1.8.7.72-1 (bug #498978) - ruby1.9 <unfixed> (bug #498977) CVE-2008-3903 (Asterisk PBX 1.2 through 1.6 and Trixbox PBX 2.6.1, when running with ...) @@ -1843,6 +1844,7 @@ {DSA-1648-1} - mon 0.99.2-13 (medium; bug #496398) CVE-2008-3790 (The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through ...) + {DSA-1652-1 DSA-1651-1} - ruby1.8 1.8.7.72-1 (bug #496808) - ruby1.9 1.9.0.2-6 (bug #497610) CVE-2008-XXXX [apertium: insecure temp files] @@ -2194,14 +2196,17 @@ - php5 5.2.6-4 (medium) NOTE: fix in pkg-php svn for both etch and sid CVE-2008-3657 (The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, ...) + {DSA-1652-1 DSA-1651-1} - ruby1.8 1.8.7.72-1 (bug #494401) - ruby1.9 1.9.0.2-6 (bug #494402) NOTE: http://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby/ CVE-2008-3656 (Algorithmic complexity vulnerability in ...) + {DSA-1652-1 DSA-1651-1} - ruby1.8 1.8.7.72-1 (bug #494401) - ruby1.9 1.9.0.2-6 (bug #494402) NOTE: http://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby/ CVE-2008-3655 (Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through ...) + {DSA-1652-1 DSA-1651-1} - ruby1.8 1.8.7.72-1 (bug #494401) - ruby1.9 1.9.0.2-6 (bug #494402) NOTE: http://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby/ @@ -4027,7 +4032,7 @@ - wireshark 1.0.1-1 (low; bug #488834) NOTE: http://www.wireshark.org/security/wnpa-sec-2008-03.html CVE-2008-2952 (liblber/io.c in OpenLDAP 2.2.4 to 2.4.10 allows remote attackers to ...) - {DTSA-151-1} + {DSA-1650-1 DTSA-151-1} - openldap2.3 <removed> (low; bug #488710) - openldap 2.4.10-3 (low; bug #488710) CVE-2008-2955 (Pidgin 2.4.1 allows remote attackers to cause a denial of service ...)