Author: carnil
Date: 2016-09-06 04:39:02 +0000 (Tue, 06 Sep 2016)
New Revision: 44358
Modified:
data/CVE/list
Log:
For now mark the unrealircd item as well with the itp (already closed though)
just for consistency, but we might need to change all of them to NFU's
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2016-09-06 04:28:39 UTC (rev 44357)
+++ data/CVE/list 2016-09-06 04:39:02 UTC (rev 44358)
@@ -1,8 +1,7 @@
CVE-2016-7145 [certificate fingerprint spoofing through crafted SASL messages]
NOT-FOR-US: Nefarious 2
CVE-2016-7144 [certificate fingerprint spoofing through crafted SASL messages]
- NOT-FOR-US: UnrealIRCd
- NOTE: There was previously a ITP as #515130
+ - unrealircd <itp> (bug #515130)
NOTE: http://www.openwall.com/lists/oss-security/2016/09/04/3
NOTE: unrealircd reportedly vulnerable, and ircd-seven reportedly not
vulnerable
CVE-2016-7143 [certificate fingerprint spoofing through crafted SASL messages]
_______________________________________________
Secure-testing-commits mailing list
[email protected]
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits