[Secure-testing-commits] r40804 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Apr 7 18:54:49 UTC 2016


Author: carnil
Date: 2016-04-07 18:54:48 +0000 (Thu, 07 Apr 2016)
New Revision: 40804

Modified:
   data/CVE/list
Log:
Add bug references for src:tiff issues

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-04-07 18:38:19 UTC (rev 40803)
+++ data/CVE/list	2016-04-07 18:54:48 UTC (rev 40804)
@@ -740,7 +740,7 @@
 	RESERVED
 CVE-2016-3631 [Illegal read in the cpStrips and cpTiles function]
 	RESERVED
-	- tiff <unfixed>
+	- tiff <unfixed> (bug #820366)
 	[jessie] - tiff <no-dsa> (Minor issue)
 	[wheezy] - tiff <no-dsa> (Minor issue)
 	- tiff3 <removed> (unimportant)
@@ -766,28 +766,28 @@
 	RESERVED
 CVE-2016-3622 [Division by zero in fpAcc function]
 	RESERVED
-	- tiff <unfixed> (low)
+	- tiff <unfixed> (low; bug #820365)
 	[jessie] - tiff <no-dsa> (Minor issue)
 	[wheezy] - tiff <no-dsa> (Minor issue)
 	- tiff3 <not-affected> (tiff tools not built)
 	NOTE: http://www.openwall.com/lists/oss-security/2016/04/07/5
 CVE-2016-3621 [Out-of-bounds Read in the bmp2tiff tool]
 	RESERVED
-	- tiff <unfixed> (low)
+	- tiff <unfixed> (low; bug #820364)
 	[jessie] - tiff <no-dsa> (Minor issue)
 	[wheezy] - tiff <no-dsa> (Minor issue)
 	- tiff3 <not-affected> (tiff tools not built)
 	NOTE: http://www.openwall.com/lists/oss-security/2016/04/07/3
 CVE-2016-3620 [Out-of-bound read in ZIPEncode]
 	RESERVED
-	- tiff <unfixed> (low)
+	- tiff <unfixed> (low; bug #820363)
 	[jessie] - tiff <no-dsa> (Minor issue)
 	[wheezy] - tiff <no-dsa> (Minor issue)
 	- tiff3 <not-affected> (tiff tools not built)
 	NOTE: http://www.openwall.com/lists/oss-security/2016/04/07/2
 CVE-2016-3619 [Memory corruption in DumpModeEncode triggered by crafted bmp file]
 	RESERVED
-	- tiff <unfixed> (low)
+	- tiff <unfixed> (low; bug #820362)
 	[jessie] - tiff <no-dsa> (Minor issue)
 	[wheezy] - tiff <no-dsa> (Minor issue)
 	- tiff3 <not-affected> (tiff tools not built)




More information about the Secure-testing-commits mailing list