Author: jmm Date: 2011-08-29 06:31:37 +0000 (Mon, 29 Aug 2011) New Revision: 17132 Modified: data/CVE/list Log: new stunnel issue (not affecting stable/oldstable) logrotate fixed in experimental Modified: data/CVE/list ==================================================================--- data/CVE/list 2011-08-28 20:40:34 UTC (rev 17131) +++ data/CVE/list 2011-08-29 06:31:37 UTC (rev 17132) @@ -825,7 +825,9 @@ CVE-2011-2941 RESERVED CVE-2011-2940 (stunnel 4.40 and 4.41 might allow remote attackers to execute ...) - TODO: check + - stunnel4 3:4.42-1 (bug #638758) + [squeeze] - stunnel4 <not-affected> (Only 4.4x affected) + [lenny] - stunnel4 <not-affected> (Only 4.4x affected) CVE-2011-2939 RESERVED CVE-2011-2938 @@ -5653,9 +5655,9 @@ [lenny] - feedparser <no-dsa> (Minor issue) NOTE: https://code.google.com/p/feedparser/issues/detail?id=91 CVE-2011-1155 (The writeState function in logrotate.c in logrotate 3.7.9 and earlier ...) - - logrotate <unfixed> + - logrotate 3.8.0-1 CVE-2011-1154 (The shred_file function in logrotate.c in logrotate 3.7.9 and earlier ...) - - logrotate <unfixed> + - logrotate 3.8.0-1 CVE-2011-1153 (Multiple format string vulnerabilities in phar_object.c in the phar ...) {DSA-2266-1} - php5 5.3.6-1 (unimportant) @@ -5875,7 +5877,7 @@ CVE-2011-1099 (Multiple directory traversal vulnerabilities in FocalMedia.Net Quick ...) NOT-FOR-US: FocalMedia.Net Quick Polls CVE-2011-1098 (Race condition in the createOutputFile function in logrotate.c in ...) - - logrotate <unfixed> + - logrotate 3.8.0-1 CVE-2011-1097 (rsync 3.x before 3.0.8, when certain recursion, deletion, and ...) - rsync <unfixed> (low; bug #621866) CVE-2011-1096