[Fedora-security-commits] fedora-security/audit f8, 1.24, 1.25 f9, 1.21, 1.22 fc7, 1.182, 1.183

fedora-security-commits at redhat.com fedora-security-commits at redhat.com
Thu Nov 22 16:01:09 UTC 2007


Author: thoger

Update of /cvs/fedora/fedora-security/audit
In directory cvs-int.fedora.redhat.com:/tmp/cvs-serv20523/audit

Modified Files:
	f8 f9 fc7 
Log Message:
blam insecure LD_LIBRARY_PATH



Index: f8
===================================================================
RCS file: /cvs/fedora/fedora-security/audit/f8,v
retrieving revision 1.24
retrieving revision 1.25
diff -u -r1.24 -r1.25
--- f8	21 Nov 2007 08:51:15 -0000	1.24
+++ f8	22 Nov 2007 16:01:07 -0000	1.25
@@ -126,6 +126,7 @@
 CVE-2006-0496 ignore (firefox) Feature, not a bug moz #324253
 CVE-2005-4809 ignore (firefox) Status bar can be modified anyways
 CVE-2005-4791 VULNERABLE (liferea) #393301
+CVE-2005-4790 VULNERABLE (blam, fixed 1.8.4) #395761
 CVE-2005-4790 backport (tomboy) #362951 [since FEDORA-2007-3253]
 CVE-2005-3675 VULNERABLE (kernel) optack, no upstream fix -- TCP protocol weakness
 CVE-2003-1265 ignore (thunderbird) Stuff deleted from userspace is not guarranteed to go away physically moz#198442


Index: f9
===================================================================
RCS file: /cvs/fedora/fedora-security/audit/f9,v
retrieving revision 1.21
retrieving revision 1.22
diff -u -r1.21 -r1.22
--- f9	21 Nov 2007 08:51:15 -0000	1.21
+++ f9	22 Nov 2007 16:01:07 -0000	1.22
@@ -121,6 +121,7 @@
 CVE-2006-0496 ignore (firefox) Feature, not a bug moz #324253
 CVE-2005-4809 ignore (firefox) Status bar can be modified anyways
 CVE-2005-4791 VULNERABLE (liferea) #393311
+CVE-2005-4790 VULNERABLE (blam, fixed 1.8.4) #395771
 CVE-2005-4790 backport (tomboy) #362961 [since tomboy-0.8.1-2.fc9]
 CVE-2005-3675 VULNERABLE (kernel) optack, no upstream fix -- TCP protocol weakness
 CVE-2003-1265 ignore (thunderbird) Stuff deleted from userspace is not guarranteed to go away physically moz#198442


Index: fc7
===================================================================
RCS file: /cvs/fedora/fedora-security/audit/fc7,v
retrieving revision 1.182
retrieving revision 1.183
diff -u -r1.182 -r1.183
--- fc7	21 Nov 2007 08:51:15 -0000	1.182
+++ fc7	22 Nov 2007 16:01:07 -0000	1.183
@@ -1385,6 +1385,7 @@
 CVE-2005-4807 ignore (binutils, gas fixed 20050721) this is a bug
 CVE-2005-4803 version (graphviz, fixed 2.2.1)
 CVE-2005-4798 version (kernel, not 2.6)
+CVE-2005-4790 VULNERABLE (blam, fixed 1.8.4) #395751
 CVE-2005-4790 backport (tomboy) #362941 [since FEDORA-2007-3011]
 CVE-2005-4784 ignore (glibc) struct dirent is big enough
 CVE-2005-4746 version (freeradius, fixed 1.0.5)




More information about the Fedora-security-commits mailing list