[Secure-testing-commits] r47562 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Dec 29 20:55:10 UTC 2016


Author: carnil
Date: 2016-12-29 20:55:10 +0000 (Thu, 29 Dec 2016)
New Revision: 47562

Modified:
   data/CVE/list
Log:
Add note for CVE-2016-10026

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-12-29 20:52:46 UTC (rev 47561)
+++ data/CVE/list	2016-12-29 20:55:10 UTC (rev 47562)
@@ -2425,6 +2425,8 @@
 	NOTE: http://ikiwiki.info/bugs/rcs_revert_can_bypass_authorization_if_affected_files_were_renamed/
 	NOTE: Fix: http://source.ikiwiki.branchable.com/?p=source.git;a=commitdiff;h=9cada49ed6ad24556dbe9861ad5b0a9f526167f9
 	NOTE: http://www.openwall.com/lists/oss-security/2016/12/20/7
+	NOTE: When fixing this issue make sure to apply the complete correct fix to
+	NOTE: not open ikiwiki to be vulnerable for CVE-2016-9645.
 CVE-2016-10025 [x86: missing NULL pointer check in VMFUNC emulation]
 	RESERVED
 	- xen 4.8.0-1




More information about the Secure-testing-commits mailing list