[Secure-testing-commits] r30535 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Dec 4 12:23:59 UTC 2014


Author: carnil
Date: 2014-12-04 12:23:59 +0000 (Thu, 04 Dec 2014)
New Revision: 30535

Modified:
   data/CVE/list
Log:
Update information for CVE-2014-9112/cpio

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-12-04 12:20:33 UTC (rev 30534)
+++ data/CVE/list	2014-12-04 12:23:59 UTC (rev 30535)
@@ -539,7 +539,10 @@
 	RESERVED
 	- cpio <unfixed>
 	NOTE: http://lcamtuf.coredump.cx/afl/vulns/lesspipe-cpio-bad-write.cpio
-	TODO: check
+	NOTE: https://savannah.gnu.org/bugs/?43709
+	NOTE: http://git.savannah.gnu.org/cgit/cpio.git/commit/?id=746f3ff6
+	NOTE: http://git.savannah.gnu.org/cgit/cpio.git/commit/?id=54d1c42a
+	NOTE: http://git.savannah.gnu.org/cgit/cpio.git/commit/?id=58df4f1b
 CVE-2014-9089 (Multiple SQL injection vulnerabilities in view_all_bug_page.php in ...)
 	- mantis <removed>
 	[squeeze] - mantis <end-of-life> (Unsupported in squeeze-lts)




More information about the Secure-testing-commits mailing list