[Secure-testing-commits] r37707 - data/CVE
Salvatore Bonaccorso
carnil at moszumanska.debian.org
Sat Nov 14 21:17:22 UTC 2015
Author: carnil
Date: 2015-11-14 21:17:22 +0000 (Sat, 14 Nov 2015)
New Revision: 37707
Modified:
data/CVE/list
Log:
Update note for libpng
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2015-11-14 21:13:51 UTC (rev 37706)
+++ data/CVE/list 2015-11-14 21:17:22 UTC (rev 37707)
@@ -49,7 +49,7 @@
CVE-2015-8126 (Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE ...)
- libpng <unfixed> (bug #805113)
NOTE: http://www.openwall.com/lists/oss-security/2015/11/12/2
- TODO: check (should be fixed in 1.6.19, 1.5.24, 1.4.17, 1.2.54, and 1.0.64)
+ NOTE: Fixed in 1.6.19, 1.5.24, 1.4.17, 1.2.54, and 1.0.64
CVE-2015-8105 (Cross-site scripting (XSS) vulnerability in program/js/app.js in ...)
- roundcube 1.1.3+dfsg.1-1
[wheezy] - roundcube <not-affected> (Vulnerable code not present)
More information about the Secure-testing-commits
mailing list