[Secure-testing-commits] r37039 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Oct 8 05:22:25 UTC 2015


Author: carnil
Date: 2015-10-08 05:22:25 +0000 (Thu, 08 Oct 2015)
New Revision: 37039

Modified:
   data/CVE/list
Log:
CVE assigned for audiofile, #801102

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2015-10-07 16:30:27 UTC (rev 37038)
+++ data/CVE/list	2015-10-08 05:22:25 UTC (rev 37039)
@@ -25,12 +25,12 @@
 CVE-2015-XXXX [arbitrary code execution issues via URLs]
 	- git 1:2.6.1-1
 	NOTE: CVE Request: http://www.openwall.com/lists/oss-security/2015/10/06/1
-CVE-2015-XXXX [When changing both sample format and number of channels, data gets corrupted; if new sample format smaller than old, possible buffer overflow]
+CVE-2015-7747 [When changing both sample format and number of channels, data gets corrupted; if new sample format smaller than old, possible buffer overflow]
 	- audiofile <unfixed> (bug #801102)
 	[wheezy] - audiofile <no-dsa> (Minor issue)
 	[jessie] - audiofile <no-dsa> (Minor issue)
 	[squeeze] - audiofile <not-affected> (Vulnerable code introduced later)
-	NOTE: CVE Request: http://www.openwall.com/lists/oss-security/2015/10/06/2
+	NOTE: http://www.openwall.com/lists/oss-security/2015/10/06/2
 CVE-2015-XXXX [gvfsd-dav: null pointer dereference if server response is not escaped]
 	- gvfs 1.23.90-1
 	[squeeze] - gvfs <no-dsa> (Minor issue)




More information about the Secure-testing-commits mailing list