[Secure-testing-commits] r41330 - data/CVE

Henri Salo fgeek-guest at moszumanska.debian.org
Sun May 1 09:39:26 UTC 2016


Author: fgeek-guest
Date: 2016-05-01 09:39:26 +0000 (Sun, 01 May 2016)
New Revision: 41330

Modified:
   data/CVE/list
Log:
CVE-2016-3991/tiff upstream notified

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-05-01 07:00:17 UTC (rev 41329)
+++ data/CVE/list	2016-05-01 09:39:26 UTC (rev 41330)
@@ -953,13 +953,14 @@
 	NOTE: http://www.openwall.com/lists/oss-security/2016/04/12/1
 CVE-2016-3996
 	RESERVED
-CVE-2016-3991
+CVE-2016-3991 [tiffcrop: out-of-bounds write in loadImage()]
 	RESERVED
 	- tiff <unfixed>
 	[jessie] - tiff <no-dsa> (Minor issue)
 	[wheezy] - tiff <no-dsa> (Minor issue)
 	- tiff3 <removed> (unimportant)
 	NOTE: src:tiff3: built binary packages do not contain the TIFF tools
+	NOTE: http://bugzilla.maptools.org/show_bug.cgi?id=2543
 CVE-2016-3990
 	RESERVED
 	- tiff <unfixed>




More information about the Secure-testing-commits mailing list