Author: jmm Date: 2011-08-21 09:07:56 +0000 (Sun, 21 Aug 2011) New Revision: 17101 Modified: data/CVE/list Log: icedove fixed, record icedove issue not affecting the Debian version Modified: data/CVE/list ==================================================================--- data/CVE/list 2011-08-20 15:55:22 UTC (rev 17100) +++ data/CVE/list 2011-08-21 09:07:56 UTC (rev 17101) @@ -394,12 +394,14 @@ [lenny] - iceweasel <not-affected> (Only affects Firefox >= 4) [squeeze] - iceweasel <not-affected> (Only affects Firefox >= 4) - iceape <not-affected> (Only affects Firefox >= 4) + - icedove <not-affected> (Only affects Thunderbird 5) CVE-2011-2991 (The browser engine in Mozilla Firefox 4.x through 5 does not properly ...) - xulrunner <not-affected> (Only affects Firefox >= 4) - iceweasel 6.0-1 [lenny] - iceweasel <not-affected> (Only affects Firefox >= 4) [squeeze] - iceweasel <not-affected> (Only affects Firefox >= 4) - iceape <not-affected> (Only affects Firefox >= 4) + - icedove <not-affected> (Only affects Thunderbird 5) CVE-2011-2990 (The implementation of Content Security Policy (CSP) violation reports ...) - xulrunner <not-affected> (Only affects Firefox >= 4) - iceweasel 6.0-1 @@ -412,29 +414,35 @@ [lenny] - iceweasel <not-affected> (Only affects Firefox >= 4) [squeeze] - iceweasel <not-affected> (Only affects Firefox >= 4) - iceape <not-affected> (Only affects Firefox >= 4) + - icedove <not-affected> (Only affects Thunderbird 5) CVE-2011-2988 (Buffer overflow in an unspecified string class in the WebGL shader ...) - xulrunner <not-affected> (Only affects Firefox >= 4) - iceweasel 6.0-1 [lenny] - iceweasel <not-affected> (Only affects Firefox >= 4) [squeeze] - iceweasel <not-affected> (Only affects Firefox >= 4) - iceape <not-affected> (Only affects Firefox >= 4) + - icedove <not-affected> (Only affects Thunderbird 5) CVE-2011-2987 (Heap-based buffer overflow in Almost Native Graphics Layer Engine ...) - xulrunner <not-affected> (Only affects Firefox >= 4) - iceweasel 6.0-1 [lenny] - iceweasel <not-affected> (Only affects Firefox >= 4) [squeeze] - iceweasel <not-affected> (Only affects Firefox >= 4) - iceape <not-affected> (Only affects Firefox >= 4) + - icedove <not-affected> (Only affects Thunderbird 5) CVE-2011-2986 (Mozilla Firefox 4.x through 5, when the Direct2D (aka D2D) API is used ...) - xulrunner <not-affected> (Only affects Windows) - iceweasel <not-affected> (Only affects Windows) + - icedove <not-affected> (Only affects Thunderbird 5) CVE-2011-2985 (Multiple unspecified vulnerabilities in the browser engine in Mozilla ...) - xulrunner <not-affected> (Only affects Firefox >= 4) - iceweasel 6.0-1 [lenny] - iceweasel <not-affected> (Only affects Firefox >= 4) [squeeze] - iceweasel <not-affected> (Only affects Firefox >= 4) - iceape <not-affected> (Only affects Firefox >= 4) + - icedove <not-affected> (Only affects Thunderbird 5) CVE-2011-2984 (Mozilla Firefox before 3.6.20 does not properly handle the dropping of ...) {DSA-2296-1 DSA-2295-1} + - icedove 3.1.12-1 - xulrunner <removed> [lenny] - xulrunner <not-affected> (Only affects Firefox >= 3.5) - iceweasel 6.0-1 @@ -443,6 +451,7 @@ [lenny] - iceape <not-affected> (Only a stub package) CVE-2011-2983 (Mozilla Firefox before 3.6.20 does not properly handle the ...) {DSA-2296-1 DSA-2295-1} + - icedove 3.1.12-1 - xulrunner <removed> [lenny] - xulrunner 1.9.0.19-13 - iceweasel 6.0-1 @@ -451,6 +460,7 @@ [lenny] - iceape <not-affected> (Only a stub package) CVE-2011-2982 (Multiple unspecified vulnerabilities in the browser engine in Mozilla ...) {DSA-2296-1 DSA-2295-1} + - icedove 3.1.12-1 - xulrunner <removed> [lenny] - xulrunner 1.9.0.19-13 - iceweasel 6.0-1 @@ -459,6 +469,7 @@ [lenny] - iceape <not-affected> (Only a stub package) CVE-2011-2981 (The event-management implementation in Mozilla Firefox before 3.6.20 ...) {DSA-2296-1 DSA-2295-1} + - icedove 3.1.12-1 - xulrunner <removed> [lenny] - xulrunner 1.9.0.19-13 - iceweasel 6.0-1 @@ -466,6 +477,7 @@ - iceape 2.0.14-5 [lenny] - iceape <not-affected> (Only a stub package) CVE-2011-2980 (Untrusted search path vulnerability in the ThinkPadSensor::Startup ...) + - icedove 3.1.12-1 - xulrunner <not-affected> (Only affects Windows) - iceweasel <not-affected> (Only affects Windows) CVE-2011-2979 (Bugzilla 4.1.x before 4.1.3 generates different responses for certain ...) @@ -1893,6 +1905,7 @@ TODO: check CVE-2011-2378 (The appendChild function in Mozilla Firefox before 3.6.20 does not ...) {DSA-2296-1 DSA-2295-1} + - icedove 3.1.12-1 - xulrunner <removed> [lenny] - xulrunner 1.9.0.19-13 - iceweasel 6.0-1 @@ -8652,11 +8665,13 @@ - icedove 3.1.11-1 CVE-2011-0084 (The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox ...) {DSA-2296-1 DSA-2295-1} + - icedove 3.1.12-1 [lenny] - xulrunner <not-affected> (Only affects Firefox >= 3.6) - iceweasel 6.0-1 [lenny] - iceweasel <not-affected> (Lenny''s iceweasel uses Xulrunner from the xulrunner source pkg) - iceape 2.0.14-5 [lenny] - iceape <not-affected> (Only a stub package) + - icedove <not-affected> (Only affects Thunderbird 5) CVE-2011-0083 (Use-after-free vulnerability in the nsSVGPathSegList::ReplaceItem ...) {DSA-2273-3 DSA-2269-1 DSA-2268-1} - iceweasel 3.5.19-3