[Secure-testing-commits] r34743 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sat Jun 6 04:12:10 UTC 2015


Author: carnil
Date: 2015-06-06 04:12:10 +0000 (Sat, 06 Jun 2015)
New Revision: 34743

Modified:
   data/CVE/list
Log:
Update CVE-2015-3210/pcre3

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-06-06 03:36:10 UTC (rev 34742)
+++ data/CVE/list	2015-06-06 04:12:10 UTC (rev 34743)
@@ -2593,8 +2593,12 @@
 CVE-2015-3210 [heap buffer overflow in pcre_compile2() / compile_regex()]
 	RESERVED
 	- pcre3 <unfixed> (bug #787433)
+	[jessie] - pcre3 <no-dsa>  (Minor issue)
+	[wheezy] - pcre3 <not-affected> (Vulnerable code introduced later)
 	NOTE: https://bugs.exim.org/show_bug.cgi?id=1636
-	NOTE: http://vcs.pcre.org/pcre?view=revision&revision=1558
+	NOTE: Fixed by: http://vcs.pcre.org/pcre?view=revision&revision=1558
+	NOTE: Affected code refactored in: http://vcs.pcre.org/pcre?view=revision&revision=1359 (8.34)
+	NOTE: Issue then introduced by: http://vcs.pcre.org/pcre?view=revision&revision=1361
 CVE-2015-3209
 	RESERVED
 CVE-2015-3208




More information about the Secure-testing-commits mailing list