[Secure-testing-commits] r33341 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Apr 2 18:16:01 UTC 2015


Author: carnil
Date: 2015-04-02 18:16:01 +0000 (Thu, 02 Apr 2015)
New Revision: 33341

Modified:
   data/CVE/list
Log:
Update status for CVE-2015-2325

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-04-02 18:03:14 UTC (rev 33340)
+++ data/CVE/list	2015-04-02 18:16:01 UTC (rev 33341)
@@ -1124,10 +1124,12 @@
 	TODO: check
 CVE-2015-2325 [heap buffer overflow in compile_branch()]
 	RESERVED
-	- pcre3 <undetermined>
+	- pcre3 <unfixed>
 	NOTE: http://bugs.exim.org/show_bug.cgi?id=1591
 	NOTE: http://vcs.pcre.org/viewvc?revision=1528&view=revision
-	TODO: check (reproducer as well available in upstream bug)
+	NOTE: Reproducer leads to "Failed: internal error: previously-checked referenced subpattern not found at offset 17"
+	NOTE: Upstream claims that it should though be the same bug:
+	NOTE: http://bugs.exim.org/show_bug.cgi?id=1591#c1
 CVE-2015-2324
 	RESERVED
 CVE-2015-2323




More information about the Secure-testing-commits mailing list