[Secure-testing-commits] r40980 - data/CVE

Matthias Geerdsen kosh-guest at moszumanska.debian.org
Mon Apr 18 19:27:20 UTC 2016


Author: kosh-guest
Date: 2016-04-18 19:27:20 +0000 (Mon, 18 Apr 2016)
New Revision: 40980

Modified:
   data/CVE/list
Log:
libxml2 parser.c included in several other packages... needs checking

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-04-18 19:09:40 UTC (rev 40979)
+++ data/CVE/list	2016-04-18 19:27:20 UTC (rev 40980)
@@ -211,6 +211,7 @@
 	NOTE: https://git.gnome.org/browse/libxml2/commit/?id=a7a94612aa3b16779e2c74e1fa353b5d9786c602
 	NOTE: https://bugzilla.gnome.org/show_bug.cgi?id=759671
 	TODO: check versions, upstream but not yet public open but referenced in commit
+	TODO: vtk6, paraview, opencollada, xdmf, gettext appear to include the affected code
 CVE-2016-3994 [GIF loader: out-of-bounds read]
 	RESERVED
 	- imlib2 <unfixed> (bug #785369)




More information about the Secure-testing-commits mailing list