[Secure-testing-commits] r46939 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Fri Dec 9 19:51:13 UTC 2016


Author: carnil
Date: 2016-12-09 19:51:13 +0000 (Fri, 09 Dec 2016)
New Revision: 46939

Modified:
   data/CVE/list
Log:
Update information for CVE-2015-8870

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-12-09 16:49:05 UTC (rev 46938)
+++ data/CVE/list	2016-12-09 19:51:13 UTC (rev 46939)
@@ -25558,9 +25558,10 @@
 	NOTE: https://github.com/dosfstools/dosfstools/issues/12
 	NOTE: https://github.com/dosfstools/dosfstools/commit/07908124838afcc99c577d1d3e84cef2dbd39cb7
 CVE-2015-8870 (Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows ...)
-	- tiff <undetermined>
-	NOTE: Fixed in 4.0.5-1 in unstable upload,  but might be as well already earlier together the CVE-2014-9330.patch
-	NOTE: already applied earlier. Should be fixed in 4.0.3-12 with the same patch as for CVE-2014-9330.
+	- tiff 4.0.3-12
+	[wheezy] - tiff 4.0.2-6+deb7u4
+	NOTE: Fixed already witht the patch applied in 4.0.3-12 in unstable for the
+	NOTE: CVE-2014-9330 issue.
 CVE-2013-7455 (Double free vulnerability in the DefaultICCintents function in ...)
 	- lcms2 2.6-1
 	[wheezy] - lcms2 <not-affected> (vulnerable code not present, no cmsPipelineFree(Lut); in Error:-part)




More information about the Secure-testing-commits mailing list