fedora-security/audit fc4,1.276,1.277 fc5,1.189,1.190

Mark Cox (mjc) fedora-extras-commits at redhat.com
Sat Jun 3 13:09:14 UTC 2006


Author: mjc

Update of /cvs/fedora/fedora-security/audit
In directory cvs-int.fedora.redhat.com:/tmp/cvs-serv30821

Modified Files:
	fc4 fc5 
Log Message:
Catch up with backlog of new cves



Index: fc4
===================================================================
RCS file: /cvs/fedora/fedora-security/audit/fc4,v
retrieving revision 1.276
retrieving revision 1.277
diff -u -r1.276 -r1.277
--- fc4	1 Jun 2006 21:28:56 -0000	1.276
+++ fc4	3 Jun 2006 13:09:11 -0000	1.277
@@ -1,14 +1,52 @@
-Up to date CVE as of CVE email 20060524
-Up to date FC4 as of 20060524
+Up to date CVE as of CVE email 20060602
+Up to date FC4 as of 20060602
 
 ** are items that need attention
 
+CVE-2006-2789 ** evolution
+CVE-2006-2788 ** firefox (note, issue caught by fc glibc)
+CVE-2006-2787 ** firefox
+CVE-2006-2787 ** thunderbird
+CVE-2006-2787 ** mozilla
+CVE-2006-2786 ** firefox
+CVE-2006-2786 ** thunderbird
+CVE-2006-2786 ** mozilla
+CVE-2006-2785 ** firefox
+CVE-2006-2785 ** mozilla
+CVE-2006-2784 ** firefox
+CVE-2006-2784 ** mozilla
+CVE-2006-2783 ** firefox
+CVE-2006-2783 ** thunderbird
+CVE-2006-2783 ** mozilla
+CVE-2006-2782 ** firefox
+CVE-2006-2781 ** thunderbird (note, issue caught by fc glibc)
+CVE-2006-2780 ** firefox
+CVE-2006-2780 ** thunderbird
+CVE-2006-2780 ** mozilla
+CVE-2006-2779 ** firefox
+CVE-2006-2779 ** thunderbird
+CVE-2006-2779 ** mozilla
+CVE-2006-2778 ** firefox
+CVE-2006-2778 ** thunderbird
+CVE-2006-2778 ** mozilla
+CVE-2006-2777 ** firefox
+CVE-2006-2777 ** thunderbird
+CVE-2006-2777 ** mozilla
+CVE-2006-2776 ** firefox
+CVE-2006-2776 ** thunderbird
+CVE-2006-2776 ** mozilla
+CVE-2006-2775 ** firefox
+CVE-2006-2775 ** thunderbird
+CVE-2006-2775 ** mozilla
+CVE-2006-2754 ** openldap
 CVE-2006-2753 VULNERABLE (mysql, fixed 4.1.20) #193828
+CVE-2006-2723 ** firefox (probably ignore)
 CVE-2006-2661 VULNERABLE (freetype, fixed 2.2.1) #183677
 CVE-2006-2656 backport (libtiff) [since FEDORA-2006-591]
 CVE-2006-2629 ** kernel
 CVE-2006-2613 ignore (firefox) This isn't an issie on FC
 CVE-2006-2607 backport (vixie-cron) #178431
+CVE-2006-2563 ** php/libcurl
 CVE-2006-2480 backport (dia) #192538 [since FEDORA-2006-580]
 CVE-2006-2453 backport (dia) #192538 [since FEDORA-2006-580]
 CVE-2006-2444 VULNERABLE (kernel, fixed 2.6.16.18)
@@ -779,6 +817,7 @@
 CVE-2005-0531 version (kernel, fixed 2.6.11)
 CVE-2005-0530 version (kernel, fixed 2.6.11)
 CVE-2005-0529 version (kernel, fixed 2.6.11)
+CVE-2005-0528 version (kernel, not 2.6)
 CVE-2005-0527 version (mozilla, fixed 1.7.6)
 CVE-2005-0527 version (firefox, fixed 1.0.1)
 CVE-2005-0525 version (php, fixed 5.0.4)
@@ -1073,6 +1112,7 @@
 CVE-2004-1005 version (mc, fixed 4.6.0)
 CVE-2004-1004 version (mc, fixed 4.6.0)
 CVE-2004-1002 ignore (ppp) not a security issue
+CVE-2004-0997 version (kernel, not 2.6)
 CVE-2004-0996 backport (cscope, not fixed in 15.5)
 CVE-2004-0990 VULNERABLE (gd)
 CVE-2004-0989 version (libxml2, fixed 2.6.15)
@@ -1275,6 +1315,7 @@
 CVE-2004-0493 version (httpd, fixed 2.0.50)
 CVE-2004-0492 version (httpd, not 2.0)
 CVE-2004-0491 version (kernel, not upstream)
+CVE-2004-0489 version (kernel, not 2.6)
 CVE-2004-0488 version (httpd, fixed 2.0.50)
 CVE-2004-0478 ignore (mozilla) not a security issue
 CVE-2004-0461 version (dhcp, fixed after 3.0.1rc13)


Index: fc5
===================================================================
RCS file: /cvs/fedora/fedora-security/audit/fc5,v
retrieving revision 1.189
retrieving revision 1.190
diff -u -r1.189 -r1.190
--- fc5	1 Jun 2006 21:28:56 -0000	1.189
+++ fc5	3 Jun 2006 13:09:11 -0000	1.190
@@ -1,14 +1,52 @@
-Up to date CVE as of CVE email 20060524
-Up to date FC5 as of 20060524
+Up to date CVE as of CVE email 20060602
+Up to date FC5 as of 20060602
 
 ** are items that need attention
 
+CVE-2006-2789 ** evolution
+CVE-2006-2788 ** firefox (note, issue caught by fc glibc)
+CVE-2006-2787 ** firefox
+CVE-2006-2787 ** thunderbird
+CVE-2006-2787 ** mozilla
+CVE-2006-2786 ** firefox
+CVE-2006-2786 ** thunderbird
+CVE-2006-2786 ** mozilla
+CVE-2006-2785 ** firefox
+CVE-2006-2785 ** mozilla
+CVE-2006-2784 ** firefox
+CVE-2006-2784 ** mozilla
+CVE-2006-2783 ** firefox
+CVE-2006-2783 ** thunderbird
+CVE-2006-2783 ** mozilla
+CVE-2006-2782 ** firefox
+CVE-2006-2781 ** thunderbird (note, issue caught by fc glibc)
+CVE-2006-2780 ** firefox
+CVE-2006-2780 ** thunderbird
+CVE-2006-2780 ** mozilla
+CVE-2006-2779 ** firefox
+CVE-2006-2779 ** thunderbird
+CVE-2006-2779 ** mozilla
+CVE-2006-2778 ** firefox
+CVE-2006-2778 ** thunderbird
+CVE-2006-2778 ** mozilla
+CVE-2006-2777 ** firefox
+CVE-2006-2777 ** thunderbird
+CVE-2006-2777 ** mozilla
+CVE-2006-2776 ** firefox
+CVE-2006-2776 ** thunderbird
+CVE-2006-2776 ** mozilla
+CVE-2006-2775 ** firefox
+CVE-2006-2775 ** thunderbird
+CVE-2006-2775 ** mozilla
+CVE-2006-2754 ** openldap
 CVE-2006-2753 VULNERABLE (mysql, fixed 5.0.22) #193828
+CVE-2006-2723 ** firefox (probably ignore)
 CVE-2006-2661 VULNERABLE (freetype, fixed 2.2.1) #183677
 CVE-2006-2656 backport (libtiff) [since FEDORA-2006-592]
 CVE-2006-2629 ** kernel
 CVE-2006-2613 ignore (firefox) This isn't an issie on FC
 CVE-2006-2607 backport (vixie-cron) #177476
+CVE-2006-2563 ** php/libcurl
 CVE-2006-2444 VULNERABLE (kernel, fixed 2.6.16.18)
 CVE-2006-2440 backport (ImageMagick) #192279 [since FEDORA-2006-588]
 CVE-2006-2414 ignore (dovecot, fixed 1.0.beta8) Not a security issue
@@ -775,6 +813,7 @@
 CVE-2005-0531 version (kernel, fixed 2.6.11)
 CVE-2005-0530 version (kernel, fixed 2.6.11)
 CVE-2005-0529 version (kernel, fixed 2.6.11)
+CVE-2005-0528 version (kernel, not 2.6)
 CVE-2005-0527 version (mozilla, fixed 1.7.6)
 CVE-2005-0527 version (firefox, fixed 1.0.1)
 CVE-2005-0525 version (php, fixed 5.0.4)
@@ -782,6 +821,7 @@
 CVE-2005-0509 version (mono, not after 1.0.5)
 CVE-2005-0504 version (kernel, not 2.6) doesn't build in 2.6
 CVE-2005-0490 version (curl, fixed 7.13.1)
+CVE-2004-0489 version (kernel, not 2.6)
 CVE-2005-0488 backport (telnet)
 CVE-2005-0488 backport (krb5) krb5-1.4.1-telnet-environ.patch
 CVE-2005-0473 version (gaim, fixed 1.1.3)
@@ -1069,6 +1109,7 @@
 CVE-2004-1005 version (mc, fixed 4.6.0)
 CVE-2004-1004 version (mc, fixed 4.6.0)
 CVE-2004-1002 ignore (ppp) not a security issue
+CVE-2004-0997 version (kernel, not 2.6)
 CVE-2004-0996 backport (cscope) not fixed in 15.5
 CVE-2004-0990 version (gd, fixed 2.0.33 at least)
 CVE-2004-0989 version (libxml2, fixed 2.6.15)




More information about the scm-commits mailing list