[Secure-testing-commits] r38080 - data/CVE
Salvatore Bonaccorso
carnil at moszumanska.debian.org
Thu Dec 3 18:21:56 UTC 2015
Author: carnil
Date: 2015-12-03 18:21:55 +0000 (Thu, 03 Dec 2015)
New Revision: 38080
Modified:
data/CVE/list
Log:
Update information for CVE-2015-8391/pcre3
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2015-12-03 18:04:07 UTC (rev 38079)
+++ data/CVE/list 2015-12-03 18:21:55 UTC (rev 38080)
@@ -6950,9 +6950,12 @@
TODO: check
CVE-2015-8391 (The pcre_compile function in pcre_compile.c in PCRE before 8.38 ...)
- pcre3 <unfixed>
+ [jessie] - pcre3 <no-dsa> (Minor issue)
+ [wheezy] - pcre3 <no-dsa> (Minor issue)
+ [squeeze] - pcre3 <not-affected> (Vulnerable code introduced later)
NOTE: Fixed in 8.38
- NOTE: http://vcs.pcre.org/pcre?view=revision&revision=1579
- TODO: check
+ NOTE: Fixed by: http://vcs.pcre.org/pcre?view=revision&revision=1579
+ NOTE: First bad commit: http://vcs.pcre.org/pcre?view=revision&revision=640
CVE-2015-8390 (PCRE before 8.38 mishandles the [: and \\ substrings in character ...)
- pcre3 <unfixed>
[jessie] - pcre3 <no-dsa> (Minor issue)
More information about the Secure-testing-commits
mailing list