[Secure-testing-commits] r43233 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sat Jul 16 05:18:34 UTC 2016


Author: carnil
Date: 2016-07-16 05:18:34 +0000 (Sat, 16 Jul 2016)
New Revision: 43233

Modified:
   data/CVE/list
Log:
Update comments for CVE-2016-5844

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-07-16 03:44:55 UTC (rev 43232)
+++ data/CVE/list	2016-07-16 05:18:34 UTC (rev 43233)
@@ -1261,11 +1261,11 @@
 	RESERVED
 CVE-2014-9863
 	RESERVED
-CVE-2016-5844
+CVE-2016-5844 [undefined behaviour (integer overflow) in iso parser]
 	RESERVED
 	- libarchive 3.2.1-1
-	NOTE: https://github.com/libarchive/libarchive/issues/717#event-697151157
-	NOTE: https://github.com/libarchive/libarchive/commit/3ad08e01b4d253c66ae56414886089684155af22
+	NOTE: Upstream ticket: https://github.com/libarchive/libarchive/issues/717
+	NOTE: Upstream fix: https://github.com/libarchive/libarchive/commit/3ad08e01b4d253c66ae56414886089684155af22 (v3.2.1)
 CVE-2016-5842
 	RESERVED
 	- imagemagick <unfixed> (bug #831034)




More information about the Secure-testing-commits mailing list