[Secure-testing-commits] r40815 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Fri Apr 8 08:29:07 UTC 2016


Author: carnil
Date: 2016-04-08 08:29:07 +0000 (Fri, 08 Apr 2016)
New Revision: 40815

Modified:
   data/CVE/list
Log:
Add three more tiff CVEs

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-04-08 07:36:20 UTC (rev 40814)
+++ data/CVE/list	2016-04-08 08:29:07 UTC (rev 40815)
@@ -705,8 +705,11 @@
 	RESERVED
 	- cacti <unfixed>
 	NOTE: http://bugs.cacti.net/view.php?id=2673
-CVE-2016-3658
+CVE-2016-3658 [Illegal read occurs in the TIFFWriteDirectoryTagLongLong8Array function in tif_dirwrite.c when using tiffset command]
 	RESERVED
+	- tiff <unfixed>
+	- tiff3 <removed>
+	TODO: check
 CVE-2016-3657
 	RESERVED
 CVE-2016-3656
@@ -753,10 +756,20 @@
 	RESERVED
 CVE-2016-3635
 	RESERVED
-CVE-2016-3634
+CVE-2016-3634 [Illegal read occurs in the tagCompare function in tif_dirinfo.c when using thumbnail command]
 	RESERVED
-CVE-2016-3633
+	- tiff <unfixed>
+	[jessie] - tiff <no-dsa> (Minor issue)
+	[wheezy] - tiff <no-dsa> (Minor issue)
+	- tiff3 <removed> (unimportant)
+	NOTE: src:tiff3: built binary packages do not contain the TIFF tools
+CVE-2016-3633 [Illegal read occurs in the _ setrow function in thumbnail]
 	RESERVED
+	- tiff <unfixed>
+	[jessie] - tiff <no-dsa> (Minor issue)
+	[wheezy] - tiff <no-dsa> (Minor issue)
+	- tiff3 <removed> (unimportant)
+	NOTE: src:tiff3: built binary packages do not contain the TIFF tools
 CVE-2016-3632 [Illegal write occurs in the _TIFFVGetField function in tif_dirinfo.c when using thumbnail]
 	RESERVED
 	- tiff <unfixed>




More information about the Secure-testing-commits mailing list