[Secure-testing-commits] r40194 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sun Mar 6 18:45:28 UTC 2016


Author: carnil
Date: 2016-03-06 18:45:28 +0000 (Sun, 06 Mar 2016)
New Revision: 40194

Modified:
   data/CVE/list
Log:
Add new openssl issue

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-03-06 18:19:12 UTC (rev 40193)
+++ data/CVE/list	2016-03-06 18:45:28 UTC (rev 40194)
@@ -1,3 +1,7 @@
+CVE-2016-XXXX [malformed private keys lead to heap corruption in OpenSSL's b2i_PVK_bio]
+	- openssl <unfixed>
+	NOTE: https://wartalker.me/a/56d62d1aeff2a2688884a075
+	TODO: check (affected versions, details, no CVE yet)
 CVE-2016-XXXX [improper validation of array index vulnerability]
 	- minissdpd <unfixed> (bug #816759)
 	NOTE: https://speirofr.appspot.com/files/advisory/SPADV-2016-02.md




More information about the Secure-testing-commits mailing list