[Fedora-security-commits] fedora-security/audit f8, 1.205, 1.206 f9, 1.195, 1.196 fc7, 1.361, 1.362

fedora-security-commits at redhat.com fedora-security-commits at redhat.com
Thu Apr 24 18:18:48 UTC 2008


Author: thoger

Update of /cvs/fedora/fedora-security/audit
In directory cvs-int.fedora.redhat.com:/tmp/cvs-serv22448/audit

Modified Files:
	f8 f9 fc7 
Log Message:
update on clamav, note mksh in F9



Index: f8
===================================================================
RCS file: /cvs/fedora/fedora-security/audit/f8,v
retrieving revision 1.205
retrieving revision 1.206
diff -u -r1.205 -r1.206
--- f8	24 Apr 2008 15:12:04 -0000	1.205
+++ f8	24 Apr 2008 18:18:18 -0000	1.206
@@ -14,7 +14,7 @@
 CVE-2008-1878 VULNERABLE (xine-lib, fixed 1.1.12.1) #443055 nsf demuxer overflow
 CVE-2008-1845 version (mksh, fixed 33d) [since FEDORA-2008-3174] 
 CVE-2008-1837 ignore (clamav, fixed 0.93) unrar code not shipped
-CVE-2008-1836 VULNERABLE (clamav, fixed 0.93) #442363 
+CVE-2008-1836 ignore (clamav, fixed 0.93) affected code introduced after 0.92.1
 CVE-2008-1835 ignore (clamav, fixed 0.93) unrar code not shipped
 CVE-2008-1833 VULNERABLE (clamav, fixed 0.93-rc1) #442363 
 CVE-2008-1796 fixed (comix) [since FEDORA-2008-2981] 


Index: f9
===================================================================
RCS file: /cvs/fedora/fedora-security/audit/f9,v
retrieving revision 1.195
retrieving revision 1.196
diff -u -r1.195 -r1.196
--- f9	24 Apr 2008 15:12:04 -0000	1.195
+++ f9	24 Apr 2008 18:18:18 -0000	1.196
@@ -11,7 +11,7 @@
 CVE-2008-1923 version (asterisk) upstream fix incomplete, resulting in CVE-2008-1897
 CVE-2008-1897 version (asterisk, fixed 1.6.0.beta3) [since asterisk-1.6.0-0.13.beta8.fc9]
 CVE-2008-1878 VULNERABLE (xine-lib, fixed 1.1.12.1) #443056 nsf demuxer overflow
-CVE-2008-1845 VULNERABLE (mksh, fixed 33d) [since mksh-33d-1.fc9] what is real impact on fedora?
+CVE-2008-1845 version (mksh, fixed 33d) [since mksh-33d-1.fc9] what is real impact on fedora?
 CVE-2008-1837 ignore (clamav, fixed 0.93) unrar code not shipped
 CVE-2008-1836 VULNERABLE (clamav, fixed 0.93) #442364 
 CVE-2008-1835 ignore (clamav, fixed 0.93) unrar code not shipped


Index: fc7
===================================================================
RCS file: /cvs/fedora/fedora-security/audit/fc7,v
retrieving revision 1.361
retrieving revision 1.362
diff -u -r1.361 -r1.362
--- fc7	24 Apr 2008 15:12:04 -0000	1.361
+++ fc7	24 Apr 2008 18:18:18 -0000	1.362
@@ -15,7 +15,7 @@
 CVE-2008-1878 VULNERABLE (xine-lib, fixed 1.1.12.1) #443054 nsf demuxer overflow
 CVE-2008-1845 version (mksh, fixed 33d) [since FEDORA-2008-3070] 
 CVE-2008-1837 ignore (clamav, fixed 0.93) unrar code not shipped
-CVE-2008-1836 VULNERABLE (clamav, fixed 0.93) #442362 
+CVE-2008-1836 ignore (clamav, fixed 0.93) affected code introduced after 0.92.1
 CVE-2008-1835 ignore (clamav, fixed 0.93) unrar code not shipped
 CVE-2008-1833 VULNERABLE (clamav, fixed 0.93-rc1) #442362 
 CVE-2008-1796 fixed (comix) [since FEDORA-2008-2993] 




More information about the Fedora-security-commits mailing list