oss-sec mailing list archives

Re: CVE requests: maradns, freeciv, rbot, gitolite, gource, shib, kvirc


From: Marcus Meissner <meissner () suse de>
Date: Thu, 24 Jun 2010 18:01:39 +0200

On Fri, Jun 11, 2010 at 02:04:26PM -0400, Josh Bressers wrote:
Steve,

Can MITRE handle this one. It's bigger than a breadbox and I lack time
to go through each of this right now.

any update?

Ciao, Marcus
 
Thanks.

-- 
    JB


----- "Moritz Muehlenhoff" <jmm () debian org> wrote:

Hi,
Please assign CVE IDs for these issues current present in the Debian
Security Tracker, but for which no CVE IDs have been assigned so far:

1. maradns
http://maradns.org/download/maradns-1.4.02-parse_segfault.patch
Fixed in 1.4.03

2. freeciv 
http://gna.org/bugs/?15624
Fixed in 2.2.1 and 2.3.0

3. rbot (http://ruby-rbot.org/)
http://www.securityfocus.com/archive/1/509719/30/0/threaded

4. gitolite
http://secunia.com/advisories/39587/
http://github.com/sitaramc/gitolite/commit/1e06fea3b6959faeb72d8dca46cd4753ada48637
http://github.com/sitaramc/gitolite/commit/5fd9328c1cd1e7c576b6530b3253061c68b159aa
http://github.com/sitaramc/gitolite/commit/5deffee3cff5f9a13c59b8c1e357c5a32487d1c3

5. gource
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=577958

6. Shibboleth:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=571631

7. kvirc
http://lists.omnikron.net/pipermail/kvirc/2010-May/000867.html

Cheers,
        Moritz


-- 
Working, but not speaking, for the following german company:
SUSE LINUX Products GmbH, GF: Markus Rex, HRB 16746 (AG Nuernberg)


Current thread: