Bug#687484: Status of CVE-2012-4414: SQL injection

2014-09-30 Thread Henri Salo
give reasoning, thank you. - --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlQqS24ACgkQXf6hBi6kbk/cCQCdGwbC8Tk1kzx1Mjg5OHDAp7wI KcwAn0NnXCiW/G9CuOQGMRk2xUODZAtm =zrVO -END PGP SIGNATURE- -- To UNSUBSCRIBE, email to debian-bugs-dist-requ

Bug#687484: Status of CVE-2012-4414: SQL injection

2014-09-30 Thread Henri Salo
give reasoning, thank you. - --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlQqS24ACgkQXf6hBi6kbk/cCQCdGwbC8Tk1kzx1Mjg5OHDAp7wI KcwAn0NnXCiW/G9CuOQGMRk2xUODZAtm =zrVO -END PGP SIGNATURE- -- To UNSUBSCRIBE, email to debian-bugs-rc-requ

[Secure-testing-commits] r29128 - data/CVE

2014-09-28 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-28 09:57:13 + (Sun, 28 Sep 2014) New Revision: 29128 Modified: data/CVE/list Log: NFU Modified: data/CVE/list === --- data/CVE/list 2014-09-28 09:51:02 UTC (rev 29127) +++ data/CVE/list

[Secure-testing-commits] r29130 - data/CVE

2014-09-28 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-28 11:50:40 + (Sun, 28 Sep 2014) New Revision: 29130 Modified: data/CVE/list Log: NFU Modified: data/CVE/list === --- data/CVE/list 2014-09-28 10:01:36 UTC (rev 29129) +++ data/CVE/list

[Secure-testing-commits] r29103 - data/CVE

2014-09-27 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-27 11:09:53 + (Sat, 27 Sep 2014) New Revision: 29103 Modified: data/CVE/list Log: NFU Modified: data/CVE/list === --- data/CVE/list 2014-09-27 10:59:45 UTC (rev 29102) +++ data/CVE/list

[Secure-testing-commits] r29075 - data/CVE

2014-09-26 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-26 14:30:50 + (Fri, 26 Sep 2014) New Revision: 29075 Modified: data/CVE/list Log: NFU Modified: data/CVE/list === --- data/CVE/list 2014-09-26 10:30:46 UTC (rev 29074) +++ data/CVE/list

[Secure-testing-commits] r29076 - data/CVE

2014-09-26 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-26 15:02:05 + (Fri, 26 Sep 2014) New Revision: 29076 Modified: data/CVE/list Log: NFU Modified: data/CVE/list === --- data/CVE/list 2014-09-26 14:30:50 UTC (rev 29075) +++ data/CVE/list

[Secure-testing-commits] r29081 - data/CVE

2014-09-26 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-26 15:42:40 + (Fri, 26 Sep 2014) New Revision: 29081 Modified: data/CVE/list Log: CVE-2014-5388/qemu fixed Modified: data/CVE/list === --- data/CVE/list 2014-09-26 15:41:57 UTC (rev

[Secure-testing-commits] r29080 - data/CVE

2014-09-26 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-26 15:41:57 + (Fri, 26 Sep 2014) New Revision: 29080 Modified: data/CVE/list Log: CVE-2014-3640/qemu fixed Modified: data/CVE/list === --- data/CVE/list 2014-09-26 15:17:58 UTC (rev

[Secure-testing-commits] r29043 - data/CVE

2014-09-25 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-25 12:26:24 + (Thu, 25 Sep 2014) New Revision: 29043 Modified: data/CVE/list Log: NFU Cisco Modified: data/CVE/list === --- data/CVE/list 2014-09-25 11:02:44 UTC (rev 29042) +++

[Secure-testing-commits] r29044 - data/CVE

2014-09-25 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-25 13:47:04 + (Thu, 25 Sep 2014) New Revision: 29044 Modified: data/CVE/list Log: NFU CVE-2014-0170 Teiid from external reference Modified: data/CVE/list === --- data/CVE/list

[Secure-testing-commits] r29045 - data/CVE

2014-09-25 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-25 13:49:51 + (Thu, 25 Sep 2014) New Revision: 29045 Modified: data/CVE/list Log: CVE-2014-6603/suricata Modified: data/CVE/list === --- data/CVE/list 2014-09-25 13:47:04 UTC (rev

[Secure-testing-commits] r29046 - data/CVE

2014-09-25 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-25 14:13:29 + (Thu, 25 Sep 2014) New Revision: 29046 Modified: data/CVE/list Log: NFU Modified: data/CVE/list === --- data/CVE/list 2014-09-25 13:49:51 UTC (rev 29045) +++ data/CVE/list

[Secure-testing-commits] r29047 - data/CVE

2014-09-25 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-25 14:26:24 + (Thu, 25 Sep 2014) New Revision: 29047 Modified: data/CVE/list Log: CVE-2014-6603/suricata bts Modified: data/CVE/list === --- data/CVE/list 2014-09-25 14:13:29 UTC (rev

[Secure-testing-commits] r29057 - data/CVE

2014-09-25 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-25 21:32:09 + (Thu, 25 Sep 2014) New Revision: 29057 Modified: data/CVE/list Log: CVE-2014-7185/python2.7 Modified: data/CVE/list === --- data/CVE/list 2014-09-25 21:14:14 UTC (rev

Bug#762828: CVE-2014-6603: suricata: Out-of-bounds access in SSH parser

2014-09-25 Thread Henri Salo
regarding this issue. - --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlQkJMMACgkQXf6hBi6kbk+bIQCgom59SVZDOvoc9gcNCJJCMgV+ noYAnizbzeHzLPFWkGt8QGm/XiMYwZ3/ =1ooE -END PGP SIGNATURE- -- To UNSUBSCRIBE, email to debian-bugs-dist-requ

[issue21831] integer overflow in 'buffer' type allows reading memory

2014-09-25 Thread Henri Salo
Henri Salo added the comment: CVE-2014-7185 -- nosy: +Henri.Salo ___ Python tracker rep...@bugs.python.org http://bugs.python.org/issue21831 ___ ___ Python-bugs-list

[Secure-testing-commits] r28994 - data/CVE

2014-09-24 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-24 10:31:55 + (Wed, 24 Sep 2014) New Revision: 28994 Modified: data/CVE/list Log: NFU Modified: data/CVE/list === --- data/CVE/list 2014-09-24 09:14:13 UTC (rev 28993) +++ data/CVE/list

[Secure-testing-commits] r28995 - data/CVE

2014-09-24 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-24 11:15:43 + (Wed, 24 Sep 2014) New Revision: 28995 Modified: data/CVE/list Log: Add mediawiki issue. I will check and submit bug when details are available Modified: data/CVE/list === ---

[Secure-testing-commits] r28997 - data/CVE

2014-09-24 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-24 13:13:01 + (Wed, 24 Sep 2014) New Revision: 28997 Modified: data/CVE/list Log: CVE-2013-0334/bundler Modified: data/CVE/list === --- data/CVE/list 2014-09-24 12:16:36 UTC (rev 28996)

Bug#762532: CVE-2014-3640: qemu: slirp: NULL pointer deref in sosendto()

2014-09-24 Thread Henri Salo
vulnerabilities so that maintainers know about them. These are also added to Debian security-tracker. In some packages maintainer is watching upstream advisories closely, but this is not always the case. I'll fix this for the next upload anyway. Thank you. - --- Henri Salo -BEGIN PGP SIGNATURE

Bug#762754: mediawiki: Enhance CSS filtering in SVG files

2014-09-24 Thread Henri Salo
) SECURITY: Enhance CSS filtering in SVG files. Filter style * elements; normalize style elements and attributes before filtering; add checks * for attributes that contain css; add unit tests for html5sec and reported * bugs. - --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU

[Secure-testing-commits] r28969 - data/CVE

2014-09-23 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-23 06:39:48 + (Tue, 23 Sep 2014) New Revision: 28969 Modified: data/CVE/list Log: add to do note from external reference Modified: data/CVE/list === --- data/CVE/list 2014-09-23

[Secure-testing-commits] r28970 - data/CVE

2014-09-23 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-23 06:58:22 + (Tue, 23 Sep 2014) New Revision: 28970 Modified: data/CVE/list Log: CVE-2014-3640/qemu bts Modified: data/CVE/list === --- data/CVE/list 2014-09-23 06:39:48 UTC (rev

[Secure-testing-commits] r28978 - data/CVE

2014-09-23 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-23 09:32:07 + (Tue, 23 Sep 2014) New Revision: 28978 Modified: data/CVE/list Log: NFU Modified: data/CVE/list === --- data/CVE/list 2014-09-23 09:14:15 UTC (rev 28977) +++ data/CVE/list

Bug#762532: CVE-2014-3640: qemu: slirp: NULL pointer deref in sosendto()

2014-09-23 Thread Henri Salo
- --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlQhGTkACgkQXf6hBi6kbk/46gCfbwwiaD3Zdfbo5z57NihRYfvJ J34An0KG/kIRMQlB9CYUgcwM9net67oc =7klY -END PGP SIGNATURE- -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject

[Secure-testing-commits] r28944 - data/CVE

2014-09-22 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-22 06:17:29 + (Mon, 22 Sep 2014) New Revision: 28944 Modified: data/CVE/list Log: CVE-2014-7143/twisted Modified: data/CVE/list === --- data/CVE/list 2014-09-22 04:32:47 UTC (rev 28943)

Bug#762393: New upstream version is available: 0.1.8

2014-09-21 Thread Henri Salo
tagged packets * added PATCH HTTP method to default method list * changed packet parsing to continue without a full header present * added PPP link type support * added custom ethernet header offset option (-S) * changed read timeout to be non-zero - --- Henri Salo -BEGIN PGP SIGNATURE

[Secure-testing-commits] r28907 - data/CVE

2014-09-19 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-19 07:05:25 + (Fri, 19 Sep 2014) New Revision: 28907 Modified: data/CVE/list Log: CVE-2014-36337/libvirt from external reference Modified: data/CVE/list === --- data/CVE/list 2014-09-19

[Secure-testing-commits] r28911 - data/CVE

2014-09-19 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-19 14:22:16 + (Fri, 19 Sep 2014) New Revision: 28911 Modified: data/CVE/list Log: CVE-2014-3633/libvirt #762203 Modified: data/CVE/list === --- data/CVE/list 2014-09-19 07:16:05 UTC

Bug#762203: CVE-2014-3633: qemu: out-of-bounds read access in qemuDomainGetBlockIoTune() due to invalid index

2014-09-19 Thread Henri Salo
/git/?p=libvirt.git;a=commitdiff;h=eca96694a7f992be633d48d5ca03cedc9bbc3c9a (v0.9.8) RedHat: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-3633 - --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlQcOvYACgkQXf6hBi6kbk8AGwCgqs/OmHigrdQtI4GGTvjipEl7

Bug#495933: question

2014-09-19 Thread Henri Salo
also be other reasons to get this into Debian. https://packages.debian.org/wheezy/fdupes Your comments are welcome. - --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlQcaTkACgkQXf6hBi6kbk+e5QCeMSutiUKDwK/Xhtg3np5ZeKBp BhsAnAu0SseiT/MzhXyyUhH/c9jZcTPj

Bug#492967: status update

2014-09-19 Thread Henri Salo
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, At least pygccxml is now in Debian[1]. Is this software still wanted to Debian? https://packages.debian.org/wheezy/python-pygccxml - --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux

Bug#494549: status

2014-09-19 Thread Henri Salo
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, It seems that site http://www.autoscan-network.com/ is down. Any other sources? Sounds like an interesting software. I would be happy to test this and after that possibly help with maintaining it if it is good enough. - --- Henri Salo -BEGIN

Bug#510207: status?

2014-09-19 Thread Henri Salo
/src' make: *** [all-recursive] Error 1 I might be interested to maintain this in the future. - - - --- Henri Salo - - -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlQcdJAACgkQXf6hBi6kbk9zlgCfUB/FZtKMpnfOuX3kj5tWnnD4 ssAAoK9JlCN+KmXmxLob01kNhk4W7Mge =prQ9

Bug#510202: status?

2014-09-19 Thread Henri Salo
this in the future. - --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlQcdhYACgkQXf6hBi6kbk8mIQCfUkKZaJdDFZb8Ac/qj5ukuhp9 xaAAnAjNPUdkkPQ0eQzYWyOV016Did9p =HJvp -END PGP SIGNATURE- -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org

Bug#479553: status

2014-09-19 Thread Henri Salo
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 URL does not work anymore. - --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlQcdv8ACgkQXf6hBi6kbk8SJACfYI/d1S8OG2HYrc3rIFogmGvi VxoAn2Qiudv2iy+ftV8OuIZldIy2KrwA =yPST -END PGP SIGNATURE

Bug#494549: status

2014-09-19 Thread Henri Salo
think this software is not widely used. If someone else says they need it I can help packaging (after testing). - --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlQciSEACgkQXf6hBi6kbk9qcwCgnjm3b1LJZx2LJqfDbw4F7Hg5 wscAoLd3nFg2E5F+OGBUnaFBrMI2lTBE =lppo

Bug#495933: question

2014-09-19 Thread Henri Salo
also be other reasons to get this into Debian. https://packages.debian.org/wheezy/fdupes Your comments are welcome. - --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlQcaTkACgkQXf6hBi6kbk+e5QCeMSutiUKDwK/Xhtg3np5ZeKBp BhsAnAu0SseiT/MzhXyyUhH/c9jZcTPj

Bug#492967: status update

2014-09-19 Thread Henri Salo
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, At least pygccxml is now in Debian[1]. Is this software still wanted to Debian? https://packages.debian.org/wheezy/python-pygccxml - --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux

Bug#494549: status

2014-09-19 Thread Henri Salo
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, It seems that site http://www.autoscan-network.com/ is down. Any other sources? Sounds like an interesting software. I would be happy to test this and after that possibly help with maintaining it if it is good enough. - --- Henri Salo -BEGIN

Bug#510207: status?

2014-09-19 Thread Henri Salo
/src' make: *** [all-recursive] Error 1 I might be interested to maintain this in the future. - - - --- Henri Salo - - -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlQcdJAACgkQXf6hBi6kbk9zlgCfUB/FZtKMpnfOuX3kj5tWnnD4 ssAAoK9JlCN+KmXmxLob01kNhk4W7Mge =prQ9

Bug#510202: status?

2014-09-19 Thread Henri Salo
this in the future. - --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlQcdhYACgkQXf6hBi6kbk8mIQCfUkKZaJdDFZb8Ac/qj5ukuhp9 xaAAnAjNPUdkkPQ0eQzYWyOV016Did9p =HJvp -END PGP SIGNATURE- -- To UNSUBSCRIBE, email to debian-wnpp-requ...@lists.debian.org

Bug#479553: status

2014-09-19 Thread Henri Salo
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 URL does not work anymore. - --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlQcdv8ACgkQXf6hBi6kbk8SJACfYI/d1S8OG2HYrc3rIFogmGvi VxoAn2Qiudv2iy+ftV8OuIZldIy2KrwA =yPST -END PGP SIGNATURE

Bug#494549: status

2014-09-19 Thread Henri Salo
think this software is not widely used. If someone else says they need it I can help packaging (after testing). - --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlQciSEACgkQXf6hBi6kbk9qcwCgnjm3b1LJZx2LJqfDbw4F7Hg5 wscAoLd3nFg2E5F+OGBUnaFBrMI2lTBE =lppo

[Secure-testing-commits] r28855 - data/CVE

2014-09-17 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-17 10:41:28 + (Wed, 17 Sep 2014) New Revision: 28855 Modified: data/CVE/list Log: NFU NS-14-030, NS-14-031 Modified: data/CVE/list === --- data/CVE/list 2014-09-17 10:40:58 UTC (rev

[Secure-testing-commits] r28867 - data/CVE

2014-09-17 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-17 14:29:06 + (Wed, 17 Sep 2014) New Revision: 28867 Modified: data/CVE/list Log: twisted issue Modified: data/CVE/list === --- data/CVE/list 2014-09-17 14:25:42 UTC (rev 28866) +++

[Secure-testing-commits] r28873 - data/CVE

2014-09-17 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-17 15:57:52 + (Wed, 17 Sep 2014) New Revision: 28873 Modified: data/CVE/list Log: Add TODOs for myself (or someone with time) Modified: data/CVE/list === --- data/CVE/list 2014-09-17

Bug#717082: comments

2014-09-17 Thread Henri Salo
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Good job. I also reported this 2014-05. If there is some test automation / CI environment I can provide test cases to detect this issue so that it does not come back in future changes. - --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG

Bug#761983: twisted: trustRoot not respected in HTTP client

2014-09-17 Thread Henri Salo
-security/2014/09/17/4 - --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlQZmd8ACgkQXf6hBi6kbk9oyACfS73uPxk0BsJBE59L310KETrR ppwAn00p+EZNY7g6A+qlKICGjAYYiarI =xPCt -END PGP SIGNATURE- -- To UNSUBSCRIBE, email to debian-bugs-dist-requ

Bug#717082: comments

2014-09-17 Thread Henri Salo
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Good job. I also reported this 2014-05. If there is some test automation / CI environment I can provide test cases to detect this issue so that it does not come back in future changes. - --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG

[Secure-testing-commits] r28822 - data/CVE

2014-09-16 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-16 15:06:31 + (Tue, 16 Sep 2014) New Revision: 28822 Modified: data/CVE/list Log: NFU ESA-2014-091 Modified: data/CVE/list === --- data/CVE/list 2014-09-16 15:03:39 UTC (rev 28821) +++

[Secure-testing-commits] r28762 - data/CVE

2014-09-14 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-14 07:06:00 + (Sun, 14 Sep 2014) New Revision: 28762 Modified: data/CVE/list Log: CVE-2014-3632/neutron from external check Modified: data/CVE/list === --- data/CVE/list 2014-09-14

Re: Switching the tracker to git

2014-09-14 Thread Henri Salo
be migrated to Git. I'm more than happy to discuss this case in detail and even help to implement it if/when team starts to move that direction. - --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlQWehsACgkQXf6hBi6kbk85kACgpTjcLWEXY8EHeqPvuCQbhs25 KX8AoKZWcUybX

[Secure-testing-commits] r28738 - data/CVE

2014-09-12 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-12 09:31:37 + (Fri, 12 Sep 2014) New Revision: 28738 Modified: data/CVE/list Log: NFU VMSA-2014-0009 Modified: data/CVE/list === --- data/CVE/list 2014-09-12 09:14:14 UTC (rev 28737)

[Secure-testing-commits] r28710 - data/CVE

2014-09-11 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-11 07:36:57 + (Thu, 11 Sep 2014) New Revision: 28710 Modified: data/CVE/list Log: CVE-2014-6311/ace Modified: data/CVE/list === --- data/CVE/list 2014-09-11 06:41:07 UTC (rev 28709) +++

[Secure-testing-commits] r28713 - data/CVE

2014-09-11 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-11 09:55:46 + (Thu, 11 Sep 2014) New Revision: 28713 Modified: data/CVE/list Log: NFU Modified: data/CVE/list === --- data/CVE/list 2014-09-11 09:14:19 UTC (rev 28712) +++ data/CVE/list

[Secure-testing-commits] r28714 - data/CVE

2014-09-11 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-11 10:05:02 + (Thu, 11 Sep 2014) New Revision: 28714 Modified: data/CVE/list Log: CVE-2014-6310 Modified: data/CVE/list === --- data/CVE/list 2014-09-11 09:55:46 UTC (rev 28713) +++

[Secure-testing-commits] r28685 - data/CVE

2014-09-10 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-10 11:54:59 + (Wed, 10 Sep 2014) New Revision: 28685 Modified: data/CVE/list Log: NFU HPSBMU03075 Modified: data/CVE/list === --- data/CVE/list 2014-09-10 11:13:11 UTC (rev 28684) +++

[Secure-testing-commits] r28688 - data/CVE

2014-09-10 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-10 14:41:19 + (Wed, 10 Sep 2014) New Revision: 28688 Modified: data/CVE/list Log: CVE-2013-/tomcat7 Modified: data/CVE/list === --- data/CVE/list 2014-09-10 14:27:30 UTC (rev 28687)

[Secure-testing-commits] r28689 - data/CVE

2014-09-10 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-10 14:45:19 + (Wed, 10 Sep 2014) New Revision: 28689 Modified: data/CVE/list Log: CVE-2013-/tomcat7 fixed long time ago Modified: data/CVE/list === --- data/CVE/list 2014-09-10

[Secure-testing-commits] r28665 - data/CVE

2014-09-09 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-09 16:59:47 + (Tue, 09 Sep 2014) New Revision: 28665 Modified: data/CVE/list Log: NFU Modified: data/CVE/list === --- data/CVE/list 2014-09-09 13:32:30 UTC (rev 28664) +++ data/CVE/list

Bug#756565: CVE

2014-09-09 Thread Henri Salo
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Have you requested CVE already? If you want I can verify this issue and create the request. - --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlQOzeYACgkQXf6hBi6kbk8dlgCdFm+h5UIJ80dqKfB0oojjiQBq

Bug#756565: CVE

2014-09-09 Thread Henri Salo
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Have you requested CVE already? If you want I can verify this issue and create the request. - --- Henri Salo -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlQOzeYACgkQXf6hBi6kbk8dlgCdFm+h5UIJ80dqKfB0oojjiQBq

[Secure-testing-commits] r28636 - data/CVE

2014-09-08 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-08 07:19:18 + (Mon, 08 Sep 2014) New Revision: 28636 Modified: data/CVE/list Log: CVE-2014-3615/qemu Modified: data/CVE/list === --- data/CVE/list 2014-09-08 04:45:04 UTC (rev 28635)

[Secure-testing-commits] r28609 - data/CVE

2014-09-05 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-05 06:35:01 + (Fri, 05 Sep 2014) New Revision: 28609 Modified: data/CVE/list Log: NFU Modified: data/CVE/list === --- data/CVE/list 2014-09-04 21:14:13 UTC (rev 28608) +++ data/CVE/list

[Secure-testing-commits] r28612 - data/CVE

2014-09-05 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-05 09:36:31 + (Fri, 05 Sep 2014) New Revision: 28612 Modified: data/CVE/list Log: Need to check CVEs from r28609 as typo3-src contain extensions. Modified: data/CVE/list === --- data/CVE/list

[Secure-testing-commits] r28592 - data/CVE

2014-09-04 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-04 06:53:11 + (Thu, 04 Sep 2014) New Revision: 28592 Modified: data/CVE/list Log: NFU CORE-2014-0005 Modified: data/CVE/list === --- data/CVE/list 2014-09-04 05:30:40 UTC (rev 28591)

[Secure-testing-commits] r28598 - data/CVE

2014-09-04 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-04 13:14:35 + (Thu, 04 Sep 2014) New Revision: 28598 Modified: data/CVE/list Log: NFU Modified: data/CVE/list === --- data/CVE/list 2014-09-04 10:46:48 UTC (rev 28597) +++ data/CVE/list

[Secure-testing-commits] r28574 - data/CVE

2014-09-03 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-03 09:02:20 + (Wed, 03 Sep 2014) New Revision: 28574 Modified: data/CVE/list Log: CVE-2014-6070 todo Modified: data/CVE/list === --- data/CVE/list 2014-09-03 07:32:20 UTC (rev 28573)

[Secure-testing-commits] r28577 - data/CVE

2014-09-03 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-03 11:10:30 + (Wed, 03 Sep 2014) New Revision: 28577 Modified: data/CVE/list Log: CVE-2014-5464/ntopng Modified: data/CVE/list === --- data/CVE/list 2014-09-03 10:48:41 UTC (rev 28576)

[Secure-testing-commits] r28580 - data/CVE

2014-09-03 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-03 14:09:31 + (Wed, 03 Sep 2014) New Revision: 28580 Modified: data/CVE/list Log: nodejs from oss-security cve request. not checked issue Modified: data/CVE/list === --- data/CVE/list

[Secure-testing-commits] r28581 - data/CVE

2014-09-03 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-03 14:25:01 + (Wed, 03 Sep 2014) New Revision: 28581 Modified: data/CVE/list Log: nodejs bts Modified: data/CVE/list === --- data/CVE/list 2014-09-03 14:09:31 UTC (rev 28580) +++

Bug#760385: nodejs: V8 Memory Corruption and Stack Overflow

2014-09-03 Thread Henri Salo
Package: nodejs Version: 0.10.29~dfsg-1 Severity: important Tags: security, fixed-upstream Hi, the following vulnerability has been fixed in nodejs v.0.10.30 http://blog.nodejs.org/2014/07/31/v8-memory-corruption-stack-overflow/ --- Henri Salo signature.asc Description: Digital signature

[Secure-testing-commits] r28566 - data/CVE

2014-09-02 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-02 17:52:08 + (Tue, 02 Sep 2014) New Revision: 28566 Modified: data/CVE/list Log: cyassl Modified: data/CVE/list === --- data/CVE/list 2014-09-02 16:40:27 UTC (rev 28565) +++

[Secure-testing-commits] r28548 - data/CVE

2014-09-01 Thread Henri Salo
Author: fgeek-guest Date: 2014-09-01 15:58:09 + (Mon, 01 Sep 2014) New Revision: 28548 Modified: data/CVE/list Log: NFU CVE-2014-5191/ckeditor, preview plugin (add-on) not included in the package Modified: data/CVE/list ===

[Secure-testing-commits] r28518 - data/CVE

2014-08-30 Thread Henri Salo
Author: fgeek-guest Date: 2014-08-30 07:38:12 + (Sat, 30 Aug 2014) New Revision: 28518 Modified: data/CVE/list Log: NFU Modified: data/CVE/list === --- data/CVE/list 2014-08-30 06:49:23 UTC (rev 28517) +++ data/CVE/list

[Secure-testing-commits] r28506 - data/CVE

2014-08-29 Thread Henri Salo
Author: fgeek-guest Date: 2014-08-29 09:34:26 + (Fri, 29 Aug 2014) New Revision: 28506 Modified: data/CVE/list Log: NFU Modified: data/CVE/list === --- data/CVE/list 2014-08-29 09:19:00 UTC (rev 28505) +++ data/CVE/list

[Secure-testing-commits] r28507 - data/CVE

2014-08-29 Thread Henri Salo
Author: fgeek-guest Date: 2014-08-29 10:33:37 + (Fri, 29 Aug 2014) New Revision: 28507 Modified: data/CVE/list Log: NFU Modified: data/CVE/list === --- data/CVE/list 2014-08-29 09:34:26 UTC (rev 28506) +++ data/CVE/list

[Secure-testing-commits] r28482 - data/CVE

2014-08-27 Thread Henri Salo
Author: fgeek-guest Date: 2014-08-27 07:05:42 + (Wed, 27 Aug 2014) New Revision: 28482 Modified: data/CVE/list Log: NFU from external check Modified: data/CVE/list === --- data/CVE/list 2014-08-27 06:51:41 UTC (rev

[Secure-testing-commits] r28472 - data/CVE

2014-08-26 Thread Henri Salo
Author: fgeek-guest Date: 2014-08-26 15:22:15 + (Tue, 26 Aug 2014) New Revision: 28472 Modified: data/CVE/list Log: NFUs Modified: data/CVE/list === --- data/CVE/list 2014-08-26 06:14:14 UTC (rev 28471) +++

[Secure-testing-commits] r28462 - data/CVE

2014-08-25 Thread Henri Salo
Author: fgeek-guest Date: 2014-08-25 11:49:10 + (Mon, 25 Aug 2014) New Revision: 28462 Modified: data/CVE/list Log: NFU HPSBMU03079 Modified: data/CVE/list === --- data/CVE/list 2014-08-25 06:30:36 UTC (rev 28461) +++

[Secure-testing-commits] r28452 - data/CVE

2014-08-24 Thread Henri Salo
Author: fgeek-guest Date: 2014-08-24 16:58:33 + (Sun, 24 Aug 2014) New Revision: 28452 Modified: data/CVE/list Log: NFU Seafile server issue Modified: data/CVE/list === --- data/CVE/list 2014-08-24 16:39:27 UTC (rev

[Secure-testing-commits] r28453 - data/CVE

2014-08-24 Thread Henri Salo
Author: fgeek-guest Date: 2014-08-24 17:13:10 + (Sun, 24 Aug 2014) New Revision: 28453 Modified: data/CVE/list Log: seafile NFU ?\226?\134?\146 itp. thanks pabs Modified: data/CVE/list === --- data/CVE/list 2014-08-24

Bug#758972: Please remove mojarra

2014-08-23 Thread Henri Salo
fixed. --- Henri Salo signature.asc Description: Digital signature __ This is the maintainer address of Debian's Java team http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-java-maintainers. Please use debian-j...@lists.debian.org for discussions and questions.

Bug#758972: data

2014-08-23 Thread Henri Salo
. --- Henri Salo signature.asc Description: Digital signature __ This is the maintainer address of Debian's Java team http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-java-maintainers. Please use debian-j...@lists.debian.org for discussions and questions.

[Secure-testing-commits] r28443 - data/CVE

2014-08-23 Thread Henri Salo
Author: fgeek-guest Date: 2014-08-23 06:23:51 + (Sat, 23 Aug 2014) New Revision: 28443 Modified: data/CVE/list Log: NFU Modified: data/CVE/list === --- data/CVE/list 2014-08-23 05:34:35 UTC (rev 28442) +++ data/CVE/list

Bug#758962: python-django-lint: Broken Vcs-Git URL

2014-08-23 Thread Henri Salo
Package: python-django-lint Version: 0.13-2 Severity: minor python-django-lint contains broken URL in: debian/control:Vcs-Git: git://github.com/lamby/pkg-django-lint.git Please see: https://github.com/lamby/django-lint http://duck.debian.net/static/sp/p/python-django-lint.html -- System

Bug#758972: Please remove mojarra

2014-08-23 Thread Henri Salo
fixed. --- Henri Salo signature.asc Description: Digital signature

Bug#758972: data

2014-08-23 Thread Henri Salo
. --- Henri Salo signature.asc Description: Digital signature

Bug#758972: Please remove mojarra

2014-08-23 Thread Henri Salo
fixed. --- Henri Salo signature.asc Description: Digital signature

Bug#758972: data

2014-08-23 Thread Henri Salo
. --- Henri Salo signature.asc Description: Digital signature

[Secure-testing-commits] r28410 - data/CVE

2014-08-21 Thread Henri Salo
Author: fgeek-guest Date: 2014-08-21 09:07:09 + (Thu, 21 Aug 2014) New Revision: 28410 Modified: data/CVE/list Log: NFU my own research :) Modified: data/CVE/list === --- data/CVE/list 2014-08-21 09:05:22 UTC (rev

Bug#758786: Dissy has been replaced by a complete re-implementation called EmilPRO

2014-08-21 Thread Henri Salo
change it you can contact me and I'll find out more details. --- Henri Salo signature.asc Description: Digital signature

[Secure-testing-commits] r28356 - data/CVE

2014-08-19 Thread Henri Salo
Author: fgeek-guest Date: 2014-08-19 10:22:33 + (Tue, 19 Aug 2014) New Revision: 28356 Modified: data/CVE/list Log: NFU ESA-2014-073, ESA-2014-059, ESA-2014-067 Modified: data/CVE/list === --- data/CVE/list 2014-08-19

[Secure-testing-commits] r28357 - data/CVE

2014-08-19 Thread Henri Salo
Author: fgeek-guest Date: 2014-08-19 10:41:06 + (Tue, 19 Aug 2014) New Revision: 28357 Modified: data/CVE/list Log: NFU ESA-2014-079 Modified: data/CVE/list === --- data/CVE/list 2014-08-19 10:22:33 UTC (rev 28356) +++

Bug#758086: CVE-2012-6153: Apache HttpComponents client: Hostname verification susceptible to MITM attack

2014-08-14 Thread Henri Salo
field was flawed. This can be exploited by a Man-in-the-middle (MITM) attack, where the attacker can spoof a valid certificate using a specially crafted subject. This issue was discovered by Florian Weimer of Red Hat Product Security. --- Henri Salo signature.asc Description: Digital signature

[Secure-testing-commits] r28267 - data/CVE

2014-08-14 Thread Henri Salo
Author: fgeek-guest Date: 2014-08-14 06:11:21 + (Thu, 14 Aug 2014) New Revision: 28267 Modified: data/CVE/list Log: NFUs Modified: data/CVE/list === --- data/CVE/list 2014-08-14 06:05:57 UTC (rev 28266) +++

[Secure-testing-commits] r28269 - data/CVE

2014-08-14 Thread Henri Salo
Author: fgeek-guest Date: 2014-08-14 06:20:20 + (Thu, 14 Aug 2014) New Revision: 28269 Modified: data/CVE/list Log: NFUs Modified: data/CVE/list === --- data/CVE/list 2014-08-14 06:13:12 UTC (rev 28268) +++

[Secure-testing-commits] r28270 - data/CVE

2014-08-14 Thread Henri Salo
Author: fgeek-guest Date: 2014-08-14 06:28:20 + (Thu, 14 Aug 2014) New Revision: 28270 Modified: data/CVE/list Log: NFUs Modified: data/CVE/list === --- data/CVE/list 2014-08-14 06:20:20 UTC (rev 28269) +++

<    7   8   9   10   11   12   13   14   15   16   >