jmm-guest at alioth.debian.org
2009-Apr-03 22:58 UTC
[Secure-testing-commits] r11560 - in data: CVE packages
Author: jmm-guest Date: 2009-04-03 22:58:08 +0000 (Fri, 03 Apr 2009) New Revision: 11560 Modified: data/CVE/list data/packages/removed-packages Log: amaya was removed Modified: data/CVE/list ==================================================================--- data/CVE/list 2009-04-03 22:00:29 UTC (rev 11559) +++ data/CVE/list 2009-04-03 22:58:08 UTC (rev 11560) @@ -91,7 +91,7 @@ - wireshark <unfixed> TODO: File bug, investigate, if necessary open RT ticket CVE-2009-1209 (Stack-based buffer overflow in W3C Amaya Web Browser 11.1 allows ...) - - amaya <unfixed> (bug filed) + - amaya <removed> CVE-2009-1208 (SQL injection vulnerability in auth2db 0.2.5, and possibly other ...) {DSA-1757-1} - auth2db 0.2.5-2+dfsg-1.1 (bug #521823; low) @@ -3520,7 +3520,7 @@ CVE-2008-5982 (Format string vulnerability in BMC PATROL Agent before 3.7.30 allows ...) NOT-FOR-US: BMC PATROL Agent CVE-2009-0323 (Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 ...) - - amaya <unfixed> (medium; bug #507587) + - amaya <removed> (medium; bug #507587) NOTE: http://www.coresecurity.com/content/amaya-buffer-overflows CVE-2009-0282 (Integer overflow in Ralink Technology USB wireless adapter (RT73) 3.08 ...) {DSA-1714-1 DSA-1713-1 DSA-1712-1} @@ -4103,7 +4103,7 @@ CVE-2008-5902 (Buffer overflow in the xrdp_bitmap_invalidate function in ...) - xrdp 0.4.0~dfsg-9 (bug #511641) CVE-2008-6005 (Multiple buffer overflows in the CheckUniqueName function in W3C Amaya ...) - - amaya <unfixed> (medium; bug #507587) + - amaya <removed> (medium; bug #507587) NOTE: different vector than described in CVE-2008-5282, see 507587#15 CVE-2009-XXXX [openslp: insecure cert validation through openssl api misuse] - openslp-dfsg <not-affected> (Debian''s openslp doesn''t build with SSL support) @@ -5820,7 +5820,7 @@ NOT-FOR-US: File Upload Manager CVE-2008-5282 (Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0.1 ...) NOTE: neither in Etch nor Lenny, removal has been proposed - - amaya <unfixed> (bug #507587) + - amaya <removed> (bug #507587) CVE-2008-5281 (Heap-based buffer overflow in Titan FTP Server 6.05 build 550 allows ...) NOT-FOR-US: Titan FTP Server CVE-2008-5280 (The Local ZIM Server in Zilab Chat and Instant Messaging (ZIM) Server ...) Modified: data/packages/removed-packages ==================================================================--- data/packages/removed-packages 2009-04-03 22:00:29 UTC (rev 11559) +++ data/packages/removed-packages 2009-04-03 22:58:08 UTC (rev 11560) @@ -210,3 +210,4 @@ libpng3 lukemftp tmsnc +amaya \ No newline at end of file