Hm?
This is patched since 0.092-2 with 01-out-of-range-error.diff
At the time where I patched it, there was no CVE ID available

Am 10.10.2010 13:19, schrieb Moritz Muehlenhoff:
Package: znc
Severity: grave
Tags: security

CVE-2010-2812 and CVE-2010-2934 are currently only
fixed in experimental, but not sid and Squeeze. The
Red Hat bug contains references to the patches:
https://bugzilla.redhat.com/show_bug.cgi?id=622600

Cheers,
         Moritz

-- System Information:
Debian Release: squeeze/sid
   APT prefers unstable
   APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.32-5-686 (SMP w/1 CPU core)
Locale: LANG=C, lc_ctype=de_de.iso-8859...@euro (charmap=ISO-8859-15)
Shell: /bin/sh linked to /bin/bash

Versions of packages znc depends on:
ii  libc6                         2.11.2-2   Embedded GNU C Library: Shared lib
ii  libgcc1                       1:4.4.4-9  GCC support library
ii  libperl5.10                   5.10.1-14  shared Perl library
ii  libssl0.9.8                   0.9.8o-1   SSL shared libraries
ii  libstdc++6                    4.4.4-9    The GNU Standard C++ Library v3

znc recommends no packages.

znc suggests no packages.






--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to