[Secure-testing-commits] r40659 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Wed Mar 30 11:26:28 UTC 2016


Author: carnil
Date: 2016-03-30 11:26:27 +0000 (Wed, 30 Mar 2016)
New Revision: 40659

Modified:
   data/CVE/list
Log:
Add CVE-2016-3616

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-03-30 11:15:57 UTC (rev 40658)
+++ data/CVE/list	2016-03-30 11:26:27 UTC (rev 40659)
@@ -143,8 +143,14 @@
 	RESERVED
 CVE-2016-3617
 	RESERVED
-CVE-2016-3616
+CVE-2016-3616 [null pointer dereference in cjpeg]
 	RESERVED
+	- libjpeg-turbo <undetermined>
+	- libjpeg9 <undetermined>
+	- libjpeg6b <undetermined>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1319661
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1318509
+	TODO: check, probably then no-dsa for all affected suites
 CVE-2016-3627 [stack exhaustion in libxml2 parsing xml files in recover mode]
 	RESERVED
 	- libxml2 <unfixed> (bug #819006)




More information about the Secure-testing-commits mailing list