[Secure-testing-commits] r31040 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Tue Dec 30 04:48:48 UTC 2014


Author: carnil
Date: 2014-12-30 04:48:48 +0000 (Tue, 30 Dec 2014)
New Revision: 31040

Modified:
   data/CVE/list
Log:
Update CVE-2014-9425/php5: not built with --with-maintainers-zts

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-12-30 02:25:32 UTC (rev 31039)
+++ data/CVE/list	2014-12-30 04:48:48 UTC (rev 31040)
@@ -407,7 +407,8 @@
 CVE-2015-0361
 	RESERVED
 CVE-2014-9425 [php5: zend_ts_hash.c double free]
-	- php5 <unfixed> (bug #774154)
+	- php5 <unfixed> (unimportant; bug #774154)
+	NOTE: php5 binary packages not built with --with-maintainer-zts
 CVE-2014-9424 [Double-free in ssl_parse_clienthello_use_srtp_ext() function]
 	- libressl <itp> (bug #754513)
 CVE-2014-9412 (Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access ...)




More information about the Secure-testing-commits mailing list