[Secure-testing-commits] r46926 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Fri Dec 9 06:43:32 UTC 2016


Author: carnil
Date: 2016-12-09 06:43:32 +0000 (Fri, 09 Dec 2016)
New Revision: 46926

Modified:
   data/CVE/list
Log:
Add note for CVE-2015-8870

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-12-09 06:37:00 UTC (rev 46925)
+++ data/CVE/list	2016-12-09 06:43:32 UTC (rev 46926)
@@ -25524,7 +25524,8 @@
 	NOTE: https://github.com/dosfstools/dosfstools/commit/07908124838afcc99c577d1d3e84cef2dbd39cb7
 CVE-2015-8870 (Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows ...)
 	- tiff <undetermined>
-	TODO: check, the exact fixing version in unstable
+	NOTE: Fixed in 4.0.5-1 in unstable upload,  but might be as well already earlier together the CVE-2014-9330.patch
+	NOTE: already applied earlier.
 CVE-2013-7455 (Double free vulnerability in the DefaultICCintents function in ...)
 	- lcms2 2.6-1
 	[wheezy] - lcms2 <not-affected> (vulnerable code not present, no cmsPipelineFree(Lut); in Error:-part)




More information about the Secure-testing-commits mailing list