Author: carnil Date: 2015-01-24 12:30:14 +0000 (Sat, 24 Jan 2015) New Revision: 31637
Modified: data/CVE/list Log: Mark fixes for openjdk-7 upload to unstable Modified: data/CVE/list =================================================================== --- data/CVE/list 2015-01-24 10:54:20 UTC (rev 31636) +++ data/CVE/list 2015-01-24 12:30:14 UTC (rev 31637) @@ -2953,7 +2953,7 @@ NOTE: Likely specific to Oracle Java, wait a bit until more details come up CVE-2015-0412 (Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 ...) - openjdk-6 <unfixed> - - openjdk-7 <unfixed> + - openjdk-7 7u75-2.5.4-1 - openjdk-8 <unfixed> CVE-2015-0411 (Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, ...) {DSA-3135-1} @@ -2964,7 +2964,7 @@ NOTE: http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html#AppendixMSQL CVE-2015-0410 (Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit ...) - openjdk-6 <unfixed> - - openjdk-7 <unfixed> + - openjdk-7 7u75-2.5.4-1 - openjdk-8 <unfixed> CVE-2015-0409 (Unspecified vulnerability in Oracle MySQL Server 5.6.21 and earlier ...) - mysql-5.5 <not-affected> (Only MySQL 5.6) @@ -2974,11 +2974,11 @@ NOTE: http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html#AppendixMSQL CVE-2015-0408 (Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and ...) - openjdk-6 <unfixed> - - openjdk-7 <unfixed> + - openjdk-7 7u75-2.5.4-1 - openjdk-8 <unfixed> CVE-2015-0407 (Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and ...) - openjdk-6 <unfixed> - - openjdk-7 <unfixed> + - openjdk-7 7u75-2.5.4-1 - openjdk-8 <unfixed> CVE-2015-0406 (Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 ...) - openjdk-6 <not-affected> (Deployment components not part of OpenJDK, only present in Oracle Java) @@ -3010,7 +3010,7 @@ TODO: check CVE-2015-0395 (Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and ...) - openjdk-6 <unfixed> - - openjdk-7 <unfixed> + - openjdk-7 7u75-2.5.4-1 - openjdk-8 <unfixed> CVE-2015-0394 (Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools ...) TODO: check @@ -3045,7 +3045,7 @@ TODO: check CVE-2015-0383 (Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and ...) - openjdk-6 <unfixed> - - openjdk-7 <unfixed> + - openjdk-7 7u75-2.5.4-1 - openjdk-8 <unfixed> CVE-2015-0382 (Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier ...) {DSA-3135-1} @@ -10850,7 +10850,7 @@ NOT-FOR-US: M/Monit CVE-2014-6601 (Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 ...) - openjdk-6 <unfixed> - - openjdk-7 <unfixed> + - openjdk-7 7u75-2.5.4-1 - openjdk-8 <unfixed> CVE-2014-6600 (Unspecified vulnerability in Oracle Sun Solaris 11 allows local users ...) TODO: check @@ -10870,13 +10870,13 @@ TODO: check CVE-2014-6593 (Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and ...) - openjdk-6 <unfixed> - - openjdk-7 <unfixed> + - openjdk-7 7u75-2.5.4-1 - openjdk-8 <unfixed> CVE-2014-6592 (Unspecified vulnerability in the Oracle OpenSSO component in Oracle ...) TODO: check CVE-2014-6591 (Unspecified vulnerability in the Java SE component in Oracle Java SE ...) - openjdk-6 <unfixed> - - openjdk-7 <unfixed> + - openjdk-7 7u75-2.5.4-1 - openjdk-8 <unfixed> - icu 52.1-7 (bug #775884) CVE-2014-6590 (Unspecified vulnerability in the Oracle VM VirtualBox component in ...) @@ -10893,13 +10893,13 @@ - virtualbox-ose <not-affected> (Introduced in 4.3) CVE-2014-6587 (Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 ...) - openjdk-6 <unfixed> - - openjdk-7 <unfixed> + - openjdk-7 7u75-2.5.4-1 - openjdk-8 <unfixed> CVE-2014-6586 (Unspecified vulnerability in the PeopleSoft Enterprise HRMS component ...) TODO: check CVE-2014-6585 (Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and ...) - openjdk-6 <unfixed> - - openjdk-7 <unfixed> + - openjdk-7 7u75-2.5.4-1 - openjdk-8 <unfixed> - icu 52.1-7 (bug #775884) CVE-2014-6584 (Unspecified vulnerability in the Integrated Lights Out Manager (ILOM) ...) @@ -18378,7 +18378,7 @@ [squeeze] - nss <no-dsa> (Upstream doesn't plan to disable SSLv3, stick with that) [wheezy] - nss <no-dsa> (Upstream doesn't plan to disable SSLv3, stick with that) - openjdk-6 <unfixed> - - openjdk-7 <unfixed> + - openjdk-7 7u75-2.5.4-1 - openjdk-8 <unfixed> - polarssl 1.3.9-2 [wheezy] - polarssl <no-dsa> (Minor issue) _______________________________________________ Secure-testing-commits mailing list Secure-testing-commits@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits