Author: joeyh Date: 2014-10-10 21:14:15 +0000 (Fri, 10 Oct 2014) New Revision: 29362
Modified: data/CVE/list Log: automatic update Modified: data/CVE/list =================================================================== --- data/CVE/list 2014-10-10 18:37:39 UTC (rev 29361) +++ data/CVE/list 2014-10-10 21:14:15 UTC (rev 29362) @@ -17598,8 +17598,8 @@ CVE-2013-7285 [remote code execution via deserialization in XStream] RESERVED - libxstream-java 1.4.7-1 (bug #734821) - [wheezy] - libxstream-java <not-affected> (Vulnerability introduced in 1.4.5) - [squeeze] - libxstream-java <not-affected> (Vulnerability introduced in 1.4.5) + [wheezy] - libxstream-java <not-affected> (Vulnerability introduced in 1.4.5) + [squeeze] - libxstream-java <not-affected> (Vulnerability introduced in 1.4.5) NOTE: http://blog.diniscruz.com/2013/12/xstream-remote-code-execution-exploit.html NOTE: http://markmail.org/message/kfqoqdfj5fnup5co?q=list:org.codehaus.xstream.dev&page=3 NOTE: initial patch: https://fisheye.codehaus.org/changelog/xstream?cs=2210 _______________________________________________ Secure-testing-commits mailing list Secure-testing-commits@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits