[Secure-testing-commits] r29673 - data/CVE

Paul Wise pabs at moszumanska.debian.org
Mon Oct 27 01:20:09 UTC 2014


Author: pabs
Date: 2014-10-27 01:20:09 +0000 (Mon, 27 Oct 2014)
New Revision: 29673

Modified:
   data/CVE/list
Log:
Add CVE-2014-8485 (thanks to twb)

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-10-26 21:35:46 UTC (rev 29672)
+++ data/CVE/list	2014-10-27 01:20:09 UTC (rev 29673)
@@ -25,6 +25,9 @@
 	NOTE: The NULL pointer dereference was introduced in https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=41061cdb98a0bec464278b4db8e894a3121671f5 (v3.17-rc1)
 	NOTE: Fix: https://git.kernel.org/cgit/virt/kvm/kvm.git/commit/?id=3f6f1480d86bf9fc16c160d803ab1d006e3058d5
 	TODO: double-check
+CVE-2014-8485
+	- binutils <unfixed>
+	NOTE: http://lcamtuf.blogspot.com.au/2014/10/psa-dont-run-strings-on-untrusted-files.html
 CVE-2014-8468
 	RESERVED
 CVE-2014-8467




More information about the Secure-testing-commits mailing list