[Secure-testing-commits] r31934 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Tue Feb 3 15:54:57 UTC 2015


Author: carnil
Date: 2015-02-03 15:54:56 +0000 (Tue, 03 Feb 2015)
New Revision: 31934

Modified:
   data/CVE/list
Log:
Add reference to CVE request for libmspack issues

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-02-03 15:25:40 UTC (rev 31933)
+++ data/CVE/list	2015-02-03 15:54:56 UTC (rev 31934)
@@ -703,12 +703,16 @@
 	NOTE: https://github.com/MegaManSec/php-src/commit/a538d2f5605798422f2746636ecdc300f8ebcaa1
 CVE-2015-XXXX [off-by-one buffer under-read in mspack/lzxd.c]
 	- libmspack 0.5-1 (bug #775499)
+	NOTE: CVE Request: http://www.openwall.com/lists/oss-security/2015/02/03/11
 CVE-2014-XXXX [null pointer dereference on a crafted CAB]
 	- libmspack 0.5-1 (bug #774665)
+	NOTE: CVE Request: http://www.openwall.com/lists/oss-security/2015/02/03/11
 CVE-2015-XXXX [off-by-one buffer over-read in mspack/mszipd.c]
 	- libmspack 0.5-1 (bug #775498)
+	NOTE: CVE Request: http://www.openwall.com/lists/oss-security/2015/02/03/11
 CVE-2015-XXXX [CHM decompression: another pointer arithmetic overflow]
 	- libmspack 0.5-1 (bug #775687)
+	NOTE: CVE Request: http://www.openwall.com/lists/oss-security/2015/02/03/11
 CVE-2015-XXXX [multiple /tmp file vulnerabilities]
 	- kamailio 4.2.0-2 (bug #775681)
 	NOTE: https://github.com/kamailio/kamailio/issues/48
@@ -2599,8 +2603,10 @@
 	NOTE: Patch used in SUSE: https://bugzilla.suse.com/attachment.cgi?id=599460&action=diff
 CVE-2015-XXXX [CHM decompression: pointer arithmetic overflow]
 	- libmspack 0.4-3 (bug #774726)
+	NOTE: CVE Request: http://www.openwall.com/lists/oss-security/2015/02/03/11
 CVE-2015-XXXX [CHM decompression: division by zero]
 	- libmspack 0.4-3 (bug #774725)
+	NOTE: CVE Request: http://www.openwall.com/lists/oss-security/2015/02/03/11
 CVE-2015-XXXX [directory traversal]
 	- arc <unfixed> (low; bug #774527)
 	[squeeze] - arc <no-dsa> (Minor issue)




More information about the Secure-testing-commits mailing list