[Secure-testing-commits] r47169 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sat Dec 17 13:25:04 UTC 2016


Author: carnil
Date: 2016-12-17 13:25:04 +0000 (Sat, 17 Dec 2016)
New Revision: 47169

Modified:
   data/CVE/list
Log:
Add CVE-2016-903{6,7}/tarantool

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-12-17 13:19:29 UTC (rev 47168)
+++ data/CVE/list	2016-12-17 13:25:04 UTC (rev 47169)
@@ -10050,10 +10050,14 @@
 	RESERVED
 CVE-2016-9038
 	RESERVED
-CVE-2016-9037
+CVE-2016-9037 [Out of bounds access in xrow_header_decode()]
 	RESERVED
-CVE-2016-9036
+	- tarantool 1.7.2.385.g952d79e-1
+	NOTE: https://github.com/tarantool/tarantool/issues/1992
+CVE-2016-9036 [Invalid handling of map16 format in mp_check()]
 	RESERVED
+	- tarantool 1.7.2.385.g952d79e-1
+	NOTE: https://github.com/tarantool/tarantool/issues/1991
 CVE-2016-9035 (An exploitable buffer overflow exists in the Joyent SmartOS ...)
 	TODO: check
 CVE-2016-9034 (An exploitable buffer overflow exists in the Joyent SmartOS ...)




More information about the Secure-testing-commits mailing list