[Secure-testing-commits] r39235 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Wed Jan 27 17:36:16 UTC 2016


Author: carnil
Date: 2016-01-27 17:36:16 +0000 (Wed, 27 Jan 2016)
New Revision: 39235

Modified:
   data/CVE/list
Log:
Mark CVE-2016-1938 as fixed in 44.0-1 but add note explaining in more detail

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-01-27 15:41:37 UTC (rev 39234)
+++ data/CVE/list	2016-01-27 17:36:16 UTC (rev 39235)
@@ -373,10 +373,13 @@
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2016-04/
 CVE-2016-1938
 	RESERVED
-	- iceweasel <unfixed>
+	- iceweasel 44.0-1
 	[jessie] - iceweasel <not-affected> (Only affects Firefox 43.x)
 	[wheezy] - iceweasel <not-affected> (Only affects Firefox 43.x)
 	[squeeze] - iceweasel <not-affected> (Only affects Firefox 43.x)
+	NOTE: Marked as fixed in 44.0-1 which would be the version fixing
+	NOTE: the issue while using the bundled nss version. iceweasel for
+	NOTE: unstable though used the system library.
 	- nss <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2016-07/
 CVE-2016-1937




More information about the Secure-testing-commits mailing list