[Secure-testing-commits] r41591 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Tue May 10 04:39:52 UTC 2016


Author: carnil
Date: 2016-05-10 04:39:52 +0000 (Tue, 10 May 2016)
New Revision: 41591

Modified:
   data/CVE/list
Log:
CVE-2016-457{0,1}/mxml assigned

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-05-10 04:36:12 UTC (rev 41590)
+++ data/CVE/list	2016-05-10 04:39:52 UTC (rev 41591)
@@ -65,10 +65,12 @@
 CVE-2016-4546
 	RESERVED
 	NOT-FOR-US: Samsung Android component
-CVE-2016-XXXX [two stack exhaustation parsing xml files using mxml]
+CVE-2016-4570 [Recursion using mxmlDelete at mxml-node.c:217 (stack-exhaustion-1.xml)]
 	- mxml <unfixed>
-	NOTE: CVE Request: http://www.openwall.com/lists/oss-security/2016/05/07/8
-	TODO: check
+	NOTE: http://www.openwall.com/lists/oss-security/2016/05/07/8
+CVE-2016-4571 [Recursion using mxml_write_node at mxml-file.c:2739 (stack-exhaustion-2.xml]
+	- mxml <unfixed>
+	NOTE: http://www.openwall.com/lists/oss-security/2016/05/07/8
 CVE-2016-XXXX [invalid pointer read]
 	- mxml <unfixed>
 	NOTE: CVE Request: http://www.openwall.com/lists/oss-security/2016/05/06/6




More information about the Secure-testing-commits mailing list