[Secure-testing-commits] r47537 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Dec 29 05:09:17 UTC 2016


Author: carnil
Date: 2016-12-29 05:09:16 +0000 (Thu, 29 Dec 2016)
New Revision: 47537

Modified:
   data/CVE/list
Log:
Revert "Mark tigervnc as not affected when closing the bug."

This reverts commit 7b72db60bf25361d463f5a7b22bcdb1f5283d077.

The patch as provided by Red Hat, which validates bytes_perl_line,
height is not applied.

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-12-29 01:43:44 UTC (rev 47536)
+++ data/CVE/list	2016-12-29 05:09:16 UTC (rev 47537)
@@ -72945,7 +72945,7 @@
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1151312
 	NOTE: Patch applied in Red Hat https://bugzilla.redhat.com/attachment.cgi?id=946490
 CVE-2014-8240 (Integer overflow in TigerVNC allows remote VNC servers to cause a ...)
-	- tigervnc <not-affected> (Vulnerable code not present as it was fixed in first upload)
+	- tigervnc <unfixed> (bug #849479)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1151307
 	NOTE: Patch https://bugzilla.redhat.com/attachment.cgi?id=947578 is not applied
 CVE-2014-8086 (Race condition in the ext4_file_write_iter function in fs/ext4/file.c ...)




More information about the Secure-testing-commits mailing list