[Secure-testing-commits] r39934 - data/CVE
Brian May
bam at moszumanska.debian.org
Fri Feb 26 01:24:50 UTC 2016
Author: bam
Date: 2016-02-26 01:24:50 +0000 (Fri, 26 Feb 2016)
New Revision: 39934
Modified:
data/CVE/list
Log:
Fix spelling
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2016-02-26 00:05:15 UTC (rev 39933)
+++ data/CVE/list 2016-02-26 01:24:50 UTC (rev 39934)
@@ -7906,15 +7906,15 @@
CVE-2015-8397 (The JPEGLSCodec::DecodeExtent function in ...)
- gdcm 2.6.2-1
[jessie] - gdcm <no-dsa> (Minor issue)
- [wheezy] - gdcm <not-affected> (Vulerable code not present)
- [squeeze] - gdcm <not-affected> (Vulerable code not present)
+ [wheezy] - gdcm <not-affected> (Vulnerable code not present)
+ [squeeze] - gdcm <not-affected> (Vulnerable code not present)
NOTE: http://census-labs.com/news/2016/01/11/gdcm-out-bounds-read-jpeglscodec-decodeextent/
NOTE: http://sourceforge.net/p/gdcm/gdcm/ci/e547b1ded3fd21e0b0ad149f13045aa12d4b9b7c/
CVE-2015-8396 (Integer overflow in the ImageRegionReader::ReadIntoBuffer function in ...)
- gdcm 2.6.2-1
[jessie] - gdcm <no-dsa> (Minor issue)
[wheezy] - gdcm <no-dsa> (Minor issue)
- [squeeze] - gdcm <not-affected> (Vulerable code not present)
+ [squeeze] - gdcm <not-affected> (Vulnerable code not present)
NOTE: http://census-labs.com/news/2016/01/11/gdcm-buffer-overflow-imageregionreaderreadintobuffer/
NOTE: http://sourceforge.net/p/gdcm/gdcm/ci/0f6f82052484774d072784f32105cecc79c45c19/
NOTE: http://sourceforge.net/p/gdcm/gdcm/ci/92cd6d7fe0d01c61cf68ac4ef65ef388ee252415/
@@ -7951,7 +7951,7 @@
NOTE: http://seclists.org/fulldisclosure/2015/Dec/att-57/cacti_sqli%281%29.txt
CVE-2015-XXXX [Avoid unbounded SFTP extended attribute key/values]
- proftpd-dfsg <unfixed>
- [squeeze] - proftpd-dfsg <not-affected> (Vulerable code not present)
+ [squeeze] - proftpd-dfsg <not-affected> (Vulnerable code not present)
NOTE: http://bugs.proftpd.org/show_bug.cgi?id=4210
NOTE: https://github.com/proftpd/proftpd/pull/171
TODO: check
@@ -7993,8 +7993,8 @@
- libraw 0.17.1-1 (bug #806809)
[jessie] - libraw 0.16.0-9+deb8u2
[wheezy] - libraw <not-affected> (Vulnerable code not present)
- [squeeze] - libraw <not-affected> (Vulerable code not present)
- - dcraw <not-affected> (Vulerable code not present)
+ [squeeze] - libraw <not-affected> (Vulnerable code not present)
+ - dcraw <not-affected> (Vulnerable code not present)
- kodi <not-affected> (Vulnerable code not present)
- darktable 2.0.0-1
[jessie] - darktable <not-affected> (Vulnerable code not present)
@@ -97648,7 +97648,7 @@
CVE-2011-4107 (The simplexml_load_string function in the XML import plug-in ...)
{DSA-2391-1}
- phpmyadmin 4:3.4.7.1-1 (bug #656247)
- [lenny] - phpmyadmin <not-affected> (Vulerable code not present)
+ [lenny] - phpmyadmin <not-affected> (Vulnerable code not present)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=751112
CVE-2011-4106 (TimThumb (timthumb.php) before 2.0 does not validate the entire source ...)
NOT-FOR-US: wordpress plugin timthumb
More information about the Secure-testing-commits
mailing list