[Fedora-security-commits] fedora-security/audit f8, 1.42, 1.43 f9, 1.37, 1.38 fc7, 1.199, 1.200

fedora-security-commits at redhat.com fedora-security-commits at redhat.com
Mon Dec 17 09:16:48 UTC 2007


Author: thoger

Update of /cvs/fedora/fedora-security/audit
In directory cvs-int.fedora.redhat.com:/tmp/cvs-serv20201/audit

Modified Files:
	f8 f9 fc7 
Log Message:
dosbox, e2fsprogs, squirrelmail, libexif, exiv2



Index: f8
===================================================================
RCS file: /cvs/fedora/fedora-security/audit/f8,v
retrieving revision 1.42
retrieving revision 1.43
diff -u -r1.42 -r1.43
--- f8	14 Dec 2007 13:55:49 -0000	1.42
+++ f8	17 Dec 2007 09:16:46 -0000	1.43
@@ -7,7 +7,12 @@
 # Up to date CVE as of CVE email 20071211
 # Up to date F8 as of 20071212
 
-CVE-2007-6321 VULENERABLE (roundcubemail) #423291
+CVE-2007-6352 VULNERABLE (exiv2) #425923
+CVE-2007-6352 VULNERABLE (libexif) #425631
+CVE-2007-6351 VULNERABLE (libexif) #425631
+CVE-2007-6348 ignore (squirrelmail) trojaned version was not shipped
+CVE-2007-6328 VULNERABLE (dosbox) design decision
+CVE-2007-6321 VULNERABLE (roundcubemail) #423291
 CVE-2007-6318 VULNERABLE (wordpress)
 CVE-2007-6304 ignore (mysql, fixed 5.0.52) federated engine not built
 CVE-2007-6303 VULNERABLE (mysql, fixed 5.0.52) #424931
@@ -64,6 +69,7 @@
 CVE-2007-5589 version (phpMyAdmin, fixed 2.11.1.2) #333661 PMASA-2007-6 [since FEDORA-2007-3636]
 CVE-2007-5501 version (kernel) [since FEDORA-2007-3837]
 CVE-2007-5500 version (kernel) [since FEDORA-2007-3837]
+CVE-2007-5497 VULNERABLE (e2fsprogs) #414581
 CVE-2007-5461 version (tomcat5) #363001 [since FEDORA-2007-3474]
 CVE-2007-5398 version (samba) [since FEDORA-2007-3403]
 CVE-2007-5395 version (link-grammar) #372351 [since FEDORA-2007-3235]


Index: f9
===================================================================
RCS file: /cvs/fedora/fedora-security/audit/f9,v
retrieving revision 1.37
retrieving revision 1.38
diff -u -r1.37 -r1.38
--- f9	14 Dec 2007 13:55:49 -0000	1.37
+++ f9	17 Dec 2007 09:16:46 -0000	1.38
@@ -7,7 +7,12 @@
 # Up to date CVE as of CVE email 20071211
 # Up to date F9 as of 20071029
 
-CVE-2007-6321 VULENERABLE (roundcubemail) #423301
+CVE-2007-6352 VULNERABLE (exiv2) #425924
+CVE-2007-6352 VULNERABLE (libexif) #425641
+CVE-2007-6351 VULNERABLE (libexif) #425641
+CVE-2007-6348 ignore (squirrelmail) trojaned version was not shipped
+CVE-2007-6328 VULNERABLE (dosbox) design decision
+CVE-2007-6321 VULNERABLE (roundcubemail) #423301
 CVE-2007-6318 VULNERABLE (wordpress)
 CVE-2007-6304 ignore (mysql, fixed 5.0.52) federated engine not built
 CVE-2007-6303 backport (mysql, fixed 5.0.52) [since mysql-5.0.45-6.fc9]
@@ -33,7 +38,7 @@
 CVE-2007-5976 version (phpMyAdmin) #385911 [since phpMyAdmin-2.11.2.2-1.fc9]
 CVE-2007-5970 ignore (mysql, fixed 5.1.23) mysql 5.1+ only, affects partitioning
 CVE-2007-5969 backport (mysql, fixed 5.0.51) [since mysql-5.0.45-6.fc9]
-CVE-2007-5964 VULNERABLE (autofs) #421371
+CVE-2007-5964 backport (autofs) #421371 [since autofs-5.0.2-21]
 CVE-2007-5960 version (mozilla, fixed ff 2.0.0.10, sm 1.1.7)
 CVE-2007-5959 version (mozilla, fixed ff 2.0.0.10, sm 1.1.7)
 CVE-2007-5947 version (mozilla, fixed ff 2.0.0.10, sm 1.1.7)
@@ -57,6 +62,7 @@
 CVE-2007-5624 version (nagios, fixed 2.10) #362811 [since nagios-2.10-3.fc9]
 CVE-2007-5623 backport (nagios-plugins, not fixed 1.4.10) #348731
 CVE-2007-5589 version (phpMyAdmin, fixed 2.11.1.2) #333661 PMASA-2007-6
+CVE-2007-5497 backport (e2fsprogs) #414591 [since e2fsprogs-1.40.2-14.fc9]
 CVE-2007-5461 VULNERABLE (tomcat5, not fixed 5.5.25) #334531
 CVE-2007-5395 version (link-grammar) #372361 [since link-grammar-4.2.5-1.fc9]
 CVE-2007-5393 backport (xpdf) #372481 [since xpdf-3.02-4.fc9]


Index: fc7
===================================================================
RCS file: /cvs/fedora/fedora-security/audit/fc7,v
retrieving revision 1.199
retrieving revision 1.200
diff -u -r1.199 -r1.200
--- fc7	14 Dec 2007 13:55:49 -0000	1.199
+++ fc7	17 Dec 2007 09:16:46 -0000	1.200
@@ -8,7 +8,12 @@
 # Up to date CVE as of CVE email 200711211
 # Up to date FC7 as of 20071212
 
-CVE-2007-6321 VULENERABLE (roundcubemail) #423281
+CVE-2007-6352 VULNERABLE (exiv2) #425922
+CVE-2007-6352 VULNERABLE (libexif) #425621
+CVE-2007-6351 VULNERABLE (libexif) #425621
+CVE-2007-6348 ignore (squirrelmail) trojaned version was not shipped
+CVE-2007-6328 VULNERABLE (dosbox) design decision
+CVE-2007-6321 VULNERABLE (roundcubemail) #423281
 CVE-2007-6318 VULNERABLE (wordpress)
 CVE-2007-6304 ignore (mysql, fixed 5.0.52) federated engine not built
 CVE-2007-6303 VULNERABLE (mysql, fixed 5.0.52) #424921
@@ -74,6 +79,7 @@
 CVE-2007-5585 backport (tempest) #336331 [since FEDORA-2007-2652]
 CVE-2007-5501 version (kernel) [since FEDORA-2007-3751]
 CVE-2007-5500 version (kernel) [since FEDORA-2007-3751]
+CVE-2007-5497 VULNERABLE (e2fsprogs) #414571
 CVE-2007-5461 version (tomcat5) #334511 [since FEDORA-2007-3456]
 CVE-2007-5416 ignore (drupal) Vulnerability in PHP<5.1.3, we're safe
 CVE-2007-5398 version (samba) [since FEDORA-2007-3402]




More information about the Fedora-security-commits mailing list