[Secure-testing-commits] r41029 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Apr 21 04:46:55 UTC 2016


Author: carnil
Date: 2016-04-21 04:46:54 +0000 (Thu, 21 Apr 2016)
New Revision: 41029

Modified:
   data/CVE/list
Log:
Update brltty entry, might actually be removed since will not get a CVE id

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-04-20 21:10:12 UTC (rev 41028)
+++ data/CVE/list	2016-04-21 04:46:54 UTC (rev 41029)
@@ -164,11 +164,11 @@
 CVE-2016-3997
 	RESERVED
 CVE-2016-XXXX [auth bypass]
-	- brltty <unfixed>
-	[wheezy] - brltty <no-dsa> (Minor issue)
-	[jessie] - brltty <no-dsa> (Minor issue)
+	- brltty <not-affected> (Vulnerable code introduced later)
 	NOTE: https://bugzilla.suse.com/show_bug.cgi?id=967436
 	NOTE: CVE Request: http://www.openwall.com/lists/oss-security/2016/04/12/4
+	NOTE: Introduced in: https://github.com/brltty/brltty/commit/e62b3c925d03239a372d425fb87b2cac65d8ef19
+	NOTE: Fixed by: https://github.com/brltty/brltty/commit/74affe7d1401f2b43ad32e18cb78704d22604ad7
 CVE-2016-XXXX [heap overflow]
 	- poppler <unfixed>
 	NOTE: https://cgit.freedesktop.org/poppler/poppler/commit/?id=b3425dd3261679958cd56c0f71995c15d2124433




More information about the Secure-testing-commits mailing list