[Secure-testing-commits] r28096 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Tue Aug 5 06:18:24 UTC 2014


Author: carnil
Date: 2014-08-05 06:18:24 +0000 (Tue, 05 Aug 2014)
New Revision: 28096

Modified:
   data/CVE/list
Log:
Add php5 entry for CVE-2014-3538

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-08-05 05:16:18 UTC (rev 28095)
+++ data/CVE/list	2014-08-05 06:18:24 UTC (rev 28096)
@@ -3807,6 +3807,8 @@
 CVE-2014-3538 (file before 5.19 does not properly restrict the amount of data read ...)
 	- file 1:5.19-1
 	NOTE: fix relies on the new feature that introduced regex/<length> syntax, might be too intrusive for backporting.
+	- php5 <unfixed>
+	NOTE: https://bugs.php.net/bug.php?id=67705
 CVE-2014-3537 (The web interface in CUPS before 1.7.4 allows local users in the lp ...)
 	{DSA-2990-1}
 	- cups 1.7.4-1




More information about the Secure-testing-commits mailing list