[kernel-sec-discuss] r2826 - active retired

Moritz Muehlenhoff jmm at alioth.debian.org
Mon Feb 25 09:34:07 UTC 2013


Author: jmm
Date: 2013-02-25 09:33:45 +0000 (Mon, 25 Feb 2013)
New Revision: 2826

Added:
   retired/CVE-2013-0216
   retired/CVE-2013-0217
Removed:
   active/CVE-2013-0216
   active/CVE-2013-0217
Modified:
   active/CVE-2013-0343
Log:
retire two issues


Deleted: active/CVE-2013-0216
===================================================================
--- active/CVE-2013-0216	2013-02-25 08:44:10 UTC (rev 2825)
+++ active/CVE-2013-0216	2013-02-25 09:33:45 UTC (rev 2826)
@@ -1,10 +0,0 @@
-Description: Linux netback DoS: memory leak on an error path which is guest triggerable.
-References:
- http://seclists.org/oss-sec/2013/q1/234
-Notes:
-Bugs:
-upstream: released (3.8-rc7) [48856286b64e4b66ec62b94e504d0b29c1ade664]
-2.6.32-upstream-stable: N/A "Not present in 2.6.32 mainline"
-sid: released (3.2.39-1)
-2.6.32-squeeze-security: released (2.6.32-48) [features/all/xen/xsa39-classic-0001-xen-netback-garbage-ring.patch]
-3.2-upstream-stable: released (3.2.39) [xen-netback-shutdown-the-ring-if-it-contains-garbage.patch]

Deleted: active/CVE-2013-0217
===================================================================
--- active/CVE-2013-0217	2013-02-25 08:44:10 UTC (rev 2825)
+++ active/CVE-2013-0217	2013-02-25 09:33:45 UTC (rev 2826)
@@ -1,10 +0,0 @@
-Description: Linux netback DoS: failure to sanity check the ring producer/consumer pointers
-References:
- http://seclists.org/oss-sec/2013/q1/234
-Notes:
-Bugs:
-upstream: released (3.8-rc7) [b9149729ebdcfce63f853aa54a404c6a8f6ebbf3]
-2.6.32-upstream-stable:  N/A "Not present in 2.6.32 mainline"
-sid: released (3.2.39-1)
-2.6.32-squeeze-security: released (2.6.32-48) [features/all/xen/xsa39-classic-0002-xen-netback-wrap-around.patch]
-3.2-upstream-stable: released (3.2.39) [netback-correct-netbk_tx_err-to-handle-wrap-around.patch]

Modified: active/CVE-2013-0343
===================================================================
--- active/CVE-2013-0343	2013-02-25 08:44:10 UTC (rev 2825)
+++ active/CVE-2013-0343	2013-02-25 09:33:45 UTC (rev 2826)
@@ -1,4 +1,4 @@
-Description: 
+Description: kernel handling of IPv6 temporary addresses
 References:
  http://seclists.org/oss-sec/2012/q4/292
  http://seclists.org/oss-sec/2013/q1/92

Copied: retired/CVE-2013-0216 (from rev 2821, active/CVE-2013-0216)
===================================================================
--- retired/CVE-2013-0216	                        (rev 0)
+++ retired/CVE-2013-0216	2013-02-25 09:33:45 UTC (rev 2826)
@@ -0,0 +1,10 @@
+Description: Linux netback DoS: memory leak on an error path which is guest triggerable.
+References:
+ http://seclists.org/oss-sec/2013/q1/234
+Notes:
+Bugs:
+upstream: released (3.8-rc7) [48856286b64e4b66ec62b94e504d0b29c1ade664]
+2.6.32-upstream-stable: N/A "Not present in 2.6.32 mainline"
+sid: released (3.2.39-1)
+2.6.32-squeeze-security: released (2.6.32-48) [features/all/xen/xsa39-classic-0001-xen-netback-garbage-ring.patch]
+3.2-upstream-stable: released (3.2.39) [xen-netback-shutdown-the-ring-if-it-contains-garbage.patch]


Property changes on: retired/CVE-2013-0216
___________________________________________________________________
Added: svn:mergeinfo
   + 

Copied: retired/CVE-2013-0217 (from rev 2822, active/CVE-2013-0217)
===================================================================
--- retired/CVE-2013-0217	                        (rev 0)
+++ retired/CVE-2013-0217	2013-02-25 09:33:45 UTC (rev 2826)
@@ -0,0 +1,10 @@
+Description: Linux netback DoS: failure to sanity check the ring producer/consumer pointers
+References:
+ http://seclists.org/oss-sec/2013/q1/234
+Notes:
+Bugs:
+upstream: released (3.8-rc7) [b9149729ebdcfce63f853aa54a404c6a8f6ebbf3]
+2.6.32-upstream-stable:  N/A "Not present in 2.6.32 mainline"
+sid: released (3.2.39-1)
+2.6.32-squeeze-security: released (2.6.32-48) [features/all/xen/xsa39-classic-0002-xen-netback-wrap-around.patch]
+3.2-upstream-stable: released (3.2.39) [netback-correct-netbk_tx_err-to-handle-wrap-around.patch]


Property changes on: retired/CVE-2013-0217
___________________________________________________________________
Added: svn:mergeinfo
   + 




More information about the kernel-sec-discuss mailing list