[Secure-testing-commits] r43031 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Wed Jul 6 08:55:35 UTC 2016


Author: carnil
Date: 2016-07-06 08:55:35 +0000 (Wed, 06 Jul 2016)
New Revision: 43031

Modified:
   data/CVE/list
Log:
Update status for CVE-2016-6163/librsvg

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-07-06 06:13:25 UTC (rev 43030)
+++ data/CVE/list	2016-07-06 08:55:35 UTC (rev 43031)
@@ -1,6 +1,7 @@
 CVE-2016-6163 [read out-of-bounds in librsvg2 (a dependency of gdk-pixbuf used to render svg images).]
-	- librsvg <undetermined>
-	TODO: Should actually be fixed already in the newes version but detemine exact version (no information from reporter)
+	- librsvg 2.40.9-2
+	NOTE: Fixed by: https://git.gnome.org/browse/librsvg/commit/?id=0035e95118a60c0cd3949c2300472d805e16a022 (2.40.7)
+	NOTE: Reproducer attached in http://seclists.org/oss-sec/2016/q3/7
 CVE-2016-6162 [BUG_ON crash in linux 4.7-rc6/master skbuff.c]
 	- linux <unfixed>
 CVE-2016-6161




More information about the Secure-testing-commits mailing list