fedora-security/audit fc4,1.211,1.212 fc5,1.125,1.126

Mark Cox (mjc) fedora-extras-commits at redhat.com
Mon Apr 24 08:17:34 UTC 2006


Author: mjc

Update of /cvs/fedora/fedora-security/audit
In directory cvs-int.fedora.redhat.com:/tmp/cvs-serv16208

Modified Files:
	fc4 fc5 
Log Message:
Finish off my fc4/fc5 catchup, check in the source that kdegraphics 3.5.2
fixed this cve upstream now (it does)



Index: fc4
===================================================================
RCS file: /cvs/fedora/fedora-security/audit/fc4,v
retrieving revision 1.211
retrieving revision 1.212
diff -u -r1.211 -r1.212
--- fc4	24 Apr 2006 07:46:17 -0000	1.211
+++ fc4	24 Apr 2006 08:17:31 -0000	1.212
@@ -1,5 +1,5 @@
 Up to date CVE as of CVE email 20060423
-Up to date FC4 as of 20060420
+Up to date FC4 as of 20060423
 
 ** are items that need attention
 
@@ -99,6 +99,7 @@
 CVE-2006-1061 version (curl, 7.15.0 - 7.15.2 only)
 CVE-2006-1059 version (samba)
 CVE-2006-1058 VULNERABLE (busybox) bz#187386
+CVE-2006-1057 VULNERABLE (gdm, fixed 2.14.1) bz#188303
 CVE-2006-1056 version (kernel, fixed 2.6.16.9) [since FEDORA-2006-423]
 CVE-2006-1055 version (kernel, fixed 2.6.17-rc1) [since FEDORA-2006-423]
 CVE-2006-1052 version (kernel, fixed 2.6.16) patch-2.6.16-rc6 [since FEDORA-2006-245]
@@ -144,7 +145,7 @@
 CVE-2006-0321 version (fetchmail, fixed 6.3.2) 6.3.X only affected
 CVE-2006-0301 version (poppler, fixed 0.4.5) [since FEDORA-2006-103]
 CVE-2006-0301 backport (xpdf) [since FEDORA-2006-104]
-CVE-2006-0301 backport (kdegraphics) [since FEDORA-2006-105]
+CVE-2006-0301 version (kdegraphics, fixed 3.5.2) [since FEDORA-2006-385] was backport since FEDORA-2006-105
 CVE-2006-0300 VULNERABLE (tar) bz#181773
 CVE-2006-0299 version (thunderbird, 1.5 only)
 CVE-2006-0299 version (mozilla, 1.8 branch only)


Index: fc5
===================================================================
RCS file: /cvs/fedora/fedora-security/audit/fc5,v
retrieving revision 1.125
retrieving revision 1.126
diff -u -r1.125 -r1.126
--- fc5	24 Apr 2006 08:05:43 -0000	1.125
+++ fc5	24 Apr 2006 08:17:31 -0000	1.126
@@ -1,5 +1,5 @@
 Up to date CVE as of CVE email 20060423
-Up to date FC5 as of 20060419
+Up to date FC5 as of 20060423
 
 ** are items that need attention
 
@@ -101,6 +101,7 @@
 CVE-2006-1061 backport (curl, fixed 7.15.3) [since FEDORA-2006-189]
 CVE-2006-1059 version (samba, fixed 3.0.22 at least) bz#187170 [since FEDORA-2006-259]
 CVE-2006-1058 VULNERABLE (busybox) bz#187386
+CVE-2006-1057 version (gdm, fixed 2.14.1) bz#188303 [since FEDORA-2006-338]
 CVE-2006-1056 version (kernel, fixed 2.6.16.9) [since FEDORA-2006-421]
 CVE-2006-1055 version (kernel, fixed 2.6.17-rc1) [since FEDORA-2006-421]
 CVE-2006-1052 version (kernel, fixed 2.6.16) patch-2.6.16-rc6 [since FEDORA-2006-233]
@@ -146,7 +147,7 @@
 CVE-2006-0321 version (fetchmail, fixed 6.3.2)
 CVE-2006-0301 version (poppler, fixed 0.4.5)
 CVE-2006-0301 backport (xpdf) xpdf-3.01pl2.patch
-CVE-2006-0301 backport (kdegraphics) post-3.5.1-kdegraphics-CVE-2006-0301.diff
+CVE-2006-0301 version (kdegraphics, fixed 3.5.2) [since FEDORA-2006-352] was backport since GA
 CVE-2006-0300 VULNERABLE (tar) [fixed rawhide in tar-1.15.1-13]
 CVE-2006-0299 version (thunderbird, fixed 1.5)
 CVE-2006-0299 version (mozilla, 1.8 branch only)
@@ -189,7 +190,7 @@
 CVE-2006-0058 version (sendmail, fixed 8.13.6) [since FEDORA-2006-193]
 CVE-2006-0052 version (mailman, fixed 2.1.6)
 CVE-2006-0049 version (gnupg, fixed 1.4.2.2)
-CVE-2006-0040 VULNERABLE (gtkhtml) no upstream fix
+CVE-2006-0040 ** VULNERABLE (gtkhtml) no upstream fix
 CVE-2006-0037 version (kernel, only 2.6.14 and 2.6.15) patch-2.6.16-rc6 [since FEDORA-2006-233]
 CVE-2006-0036 version (kernel, only 2.6.14 and 2.6.15) patch-2.6.16-rc6 [since FEDORA-2006-233]
 CVE-2006-0035 version (kernel, only 2.6.14 and 2.6.15) patch-2.6.16-rc6 [since FEDORA-2006-233]




More information about the fedora-extras-commits mailing list