[Secure-testing-team] [Secure-testing-commits] r12595 - in data: CVE DSA

Michael S Gilbert michael.s.gilbert at gmail.com
Fri Aug 14 20:34:24 UTC 2009


On Fri, Aug 14, 2009 at 4:16 PM, Giuseppe Iuculano wrote:
> --- data/DSA/list       2009-08-14 19:31:52 UTC (rev 12594)
> +++ data/DSA/list       2009-08-14 20:16:54 UTC (rev 12595)
> @@ -2055,7 +2055,7 @@
>        {CVE-2007-0005 CVE-2007-0958 CVE-2007-1357 CVE-2007-1592}
>        [etch] - linux-2.6 2.6.18.dfsg.1-12etch1
>  [01 May 2007] DSA-1285-1 wordpress
> -       {CVE-2007-1622 CVE-2007-1893 CVE-2007-1894 CVE-2007-1897}
> +       {CVE-2007-1622 CVE-2007-1893 CVE-2007-1894 CVE-2007-1897 CVE-2007-4483}
>        [etch] - wordpress 2.0.10-1
>  [01 May 2007] DSA-1284-1 qemu
>        {CVE-2007-1320 CVE-2007-1321 CVE-2007-1322 CVE-2007-1366 CVE-2007-5729 CVE-2007-5730}

i  don't mean to question the accuracy of this change, but just out of
curiousity, how did an issue with a cve assigned in august 2007 [0]
get fixed in may 2007?  i understand that that's a short (3 month)
difference and debian could have been aware ahead of cve assignment.

mike

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4483



More information about the Secure-testing-team mailing list