[Secure-testing-commits] r32376 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sat Feb 21 09:31:55 UTC 2015


Author: carnil
Date: 2015-02-21 09:26:34 +0000 (Sat, 21 Feb 2015)
New Revision: 32376

Modified:
   data/CVE/list
Log:
Add CVE-2015-0273/php5, left TODO since not checked

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-02-21 08:56:43 UTC (rev 32375)
+++ data/CVE/list	2015-02-21 09:26:34 UTC (rev 32376)
@@ -6654,8 +6654,13 @@
 	RESERVED
 CVE-2015-0274
 	RESERVED
-CVE-2015-0273
+CVE-2015-0273 [use after free vulnerability in unserialize() with DateTimeZone]
 	RESERVED
+	- php5 <unfixed>
+	NOTE: https://bugs.php.net/bug.php?id=68942
+	NOTE: http://git.php.net/?p=php-src.git;a=commit;h=c377f1a715476934133f3254d1e0d4bf3743e2d2
+	NOTE: http://git.php.net/?p=php-src.git;a=commit;h=71335e6ebabc1b12c057d8017fd811892ecdfd24
+	TODO: check
 CVE-2015-0272
 	RESERVED
 CVE-2015-0271




More information about the Secure-testing-commits mailing list