[Secure-testing-commits] r27496 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Fri Jun 27 12:12:14 UTC 2014


Author: carnil
Date: 2014-06-27 12:12:14 +0000 (Fri, 27 Jun 2014)
New Revision: 27496

Modified:
   data/CVE/list
Log:
Add CVE-2014-3487/{file,php5}

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-06-27 12:01:14 UTC (rev 27495)
+++ data/CVE/list	2014-06-27 12:12:14 UTC (rev 27496)
@@ -2526,8 +2526,12 @@
 	RESERVED
 	- netty <not-affected> (Introduced in 3.9.0)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1107983 says only affects 3.9.0 and 3.9.1
-CVE-2014-3487
+CVE-2014-3487 [cdf_read_property_info insufficient boundary check]
 	RESERVED
+	- file 1:5.19-1
+	NOTE: https://github.com/file/file/commit/93e063ee374b6a75729df9e7201fb511e47e259d
+	- php5 5.6.0~rc1+dfsg-1
+	NOTE: http://git.php.net/?p=php-src.git;a=commit;h=25b1dc917a53787dbb2532721ca22f3f36eb13c0
 CVE-2014-3486
 	RESERVED
 CVE-2014-3485




More information about the Secure-testing-commits mailing list