[Secure-testing-commits] r41919 - data/CVE

security tracker role sectracker at moszumanska.debian.org
Fri May 20 21:10:11 UTC 2016


Author: sectracker
Date: 2016-05-20 21:10:11 +0000 (Fri, 20 May 2016)
New Revision: 41919

Modified:
   data/CVE/list
Log:
automatic update

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-05-20 21:03:37 UTC (rev 41918)
+++ data/CVE/list	2016-05-20 21:10:11 UTC (rev 41919)
@@ -2574,8 +2574,7 @@
 	- imlib2 1.4.8-1 (bug #785369)
 	NOTE: https://git.enlightenment.org/legacy/imlib2.git/commit/?id=37a96801663b7b4cd3fbe56cc0eb8b6a17e766a8
 	NOTE: http://www.openwall.com/lists/oss-security/2016/04/09/6
-CVE-2016-4070 [Integer overflow in php_raw_url_encode]
-	RESERVED
+CVE-2016-4070 (** DISPUTED ** Integer overflow in the php_raw_url_encode function in ...)
 	{DSA-3560-1}
 	- php7.0 7.0.5-1
 	- php5 5.6.20+dfsg-1
@@ -2583,8 +2582,7 @@
 	NOTE: https://bugs.php.net/bug.php?id=71798
 	NOTE: https://git.php.net/?p=php-src.git;a=commit;h=95433e8e339dbb6b5d5541473c1661db6ba2c451
 	NOTE: http://www.openwall.com/lists/oss-security/2016/04/11/7
-CVE-2016-4071 [Format string vulnerability in php_snmp_error()]
-	RESERVED
+CVE-2016-4071 (Format string vulnerability in the php_snmp_error function in ...)
 	{DSA-3560-1}
 	- php7.0 7.0.5-1
 	- php5 5.6.20+dfsg-1
@@ -2592,8 +2590,7 @@
 	NOTE: https://bugs.php.net/bug.php?id=71704
 	NOTE: https://git.php.net/?p=php-src.git;a=commit;h=6e25966544fb1d2f3d7596e060ce9c9269bbdcf8
 	NOTE: http://www.openwall.com/lists/oss-security/2016/04/11/7
-CVE-2016-4072 [Invalid memory write in phar on filename containing \0 inside name]
-	RESERVED
+CVE-2016-4072 (The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x ...)
 	{DSA-3560-1}
 	- php7.0 7.0.5-1
 	- php5 5.6.20+dfsg-1
@@ -2602,8 +2599,7 @@
 	NOTE: https://gist.github.com/smalyshev/80b5c2909832872f2ba2
 	NOTE: https://git.php.net/?p=php-src.git;a=commit;h=1e9b175204e3286d64dfd6c9f09151c31b5e099a
 	NOTE: http://www.openwall.com/lists/oss-security/2016/04/11/7
-CVE-2016-4073 [Negative size parameter in memcpy]
-	RESERVED
+CVE-2016-4073 (Multiple integer overflows in the mbfl_strcut function in ...)
 	{DSA-3560-1}
 	- php7.0 7.0.5-1
 	- php5 5.6.20+dfsg-1
@@ -2729,8 +2725,7 @@
 	- tiff3 <removed> (unimportant)
 	NOTE: src:tiff3: built binary packages do not contain the TIFF tools
 	NOTE: http://bugzilla.maptools.org/show_bug.cgi?id=2545
-CVE-2015-8865 [Buffer over-write in finfo_open with malformed magic file]
-	RESERVED
+CVE-2015-8865 (The file_check_mem function in funcs.c in file before 5.23, as used in ...)
 	{DSA-3560-1 DLA-460-1}
 	- php7.0 7.0.5-1
 	- php5 5.6.20+dfsg-1
@@ -9156,146 +9151,146 @@
 	RESERVED
 CVE-2016-1860
 	RESERVED
-CVE-2016-1859
-	RESERVED
-CVE-2016-1858
-	RESERVED
-CVE-2016-1857
-	RESERVED
-CVE-2016-1856
-	RESERVED
-CVE-2016-1855
-	RESERVED
-CVE-2016-1854
-	RESERVED
-CVE-2016-1853
-	RESERVED
-CVE-2016-1852
-	RESERVED
-CVE-2016-1851
-	RESERVED
-CVE-2016-1850
-	RESERVED
-CVE-2016-1849
-	RESERVED
-CVE-2016-1848
-	RESERVED
-CVE-2016-1847
-	RESERVED
-CVE-2016-1846
-	RESERVED
+CVE-2016-1859 (The WebKit Canvas implementation in Apple iOS before 9.3.2, Safari ...)
+	TODO: check
+CVE-2016-1858 (WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and ...)
+	TODO: check
+CVE-2016-1857 (WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and ...)
+	TODO: check
+CVE-2016-1856 (WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and ...)
+	TODO: check
+CVE-2016-1855 (WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and ...)
+	TODO: check
+CVE-2016-1854 (WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and ...)
+	TODO: check
+CVE-2016-1853 (Tcl in Apple OS X before 10.11.5 allows remote attackers to obtain ...)
+	TODO: check
+CVE-2016-1852 (Siri in Apple iOS before 9.3.2 does not block data detectors within ...)
+	TODO: check
+CVE-2016-1851 (The Screen Lock feature in Apple OS X before 10.11.5 mishandles ...)
+	TODO: check
+CVE-2016-1850 (SceneKit in Apple OS X before 10.11.5 allows remote attackers to ...)
+	TODO: check
+CVE-2016-1849 (The "Clear History and Website Data" feature in Apple Safari before ...)
+	TODO: check
+CVE-2016-1848 (QuickTime in Apple OS X before 10.11.5 allows remote attackers to ...)
+	TODO: check
+CVE-2016-1847 (OpenGL, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+	TODO: check
+CVE-2016-1846 (The NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 ...)
+	TODO: check
 CVE-2016-1845
 	RESERVED
-CVE-2016-1844
-	RESERVED
-CVE-2016-1843
-	RESERVED
-CVE-2016-1842
-	RESERVED
-CVE-2016-1841
-	RESERVED
-CVE-2016-1840
-	RESERVED
-CVE-2016-1839
-	RESERVED
-CVE-2016-1838
-	RESERVED
-CVE-2016-1837
-	RESERVED
-CVE-2016-1836
-	RESERVED
-CVE-2016-1835
-	RESERVED
-CVE-2016-1834
-	RESERVED
-CVE-2016-1833
-	RESERVED
-CVE-2016-1832
-	RESERVED
-CVE-2016-1831
-	RESERVED
-CVE-2016-1830
-	RESERVED
-CVE-2016-1829
-	RESERVED
-CVE-2016-1828
-	RESERVED
-CVE-2016-1827
-	RESERVED
-CVE-2016-1826
-	RESERVED
-CVE-2016-1825
-	RESERVED
-CVE-2016-1824
-	RESERVED
-CVE-2016-1823
-	RESERVED
-CVE-2016-1822
-	RESERVED
-CVE-2016-1821
-	RESERVED
-CVE-2016-1820
-	RESERVED
-CVE-2016-1819
-	RESERVED
-CVE-2016-1818
-	RESERVED
-CVE-2016-1817
-	RESERVED
-CVE-2016-1816
-	RESERVED
-CVE-2016-1815
-	RESERVED
-CVE-2016-1814
-	RESERVED
-CVE-2016-1813
-	RESERVED
-CVE-2016-1812
-	RESERVED
-CVE-2016-1811
-	RESERVED
-CVE-2016-1810
-	RESERVED
-CVE-2016-1809
-	RESERVED
-CVE-2016-1808
-	RESERVED
-CVE-2016-1807
-	RESERVED
-CVE-2016-1806
-	RESERVED
-CVE-2016-1805
-	RESERVED
-CVE-2016-1804
-	RESERVED
-CVE-2016-1803
-	RESERVED
-CVE-2016-1802
-	RESERVED
-CVE-2016-1801
-	RESERVED
-CVE-2016-1800
-	RESERVED
-CVE-2016-1799
-	RESERVED
-CVE-2016-1798
-	RESERVED
-CVE-2016-1797
-	RESERVED
-CVE-2016-1796
-	RESERVED
-CVE-2016-1795
-	RESERVED
-CVE-2016-1794
-	RESERVED
-CVE-2016-1793
-	RESERVED
-CVE-2016-1792
-	RESERVED
-CVE-2016-1791
-	RESERVED
-CVE-2016-1790
-	RESERVED
+CVE-2016-1844 (The Messages component in Apple OS X before 10.11.5 mishandles roster ...)
+	TODO: check
+CVE-2016-1843 (The Messages component in Apple OS X before 10.11.5 mishandles ...)
+	TODO: check
+CVE-2016-1842 (MapKit in Apple iOS before 9.3.2, OS X before 10.11.5, and watchOS ...)
+	TODO: check
+CVE-2016-1841 (libxslt, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+	TODO: check
+CVE-2016-1840 (libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+	TODO: check
+CVE-2016-1839 (libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+	TODO: check
+CVE-2016-1838 (libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+	TODO: check
+CVE-2016-1837 (libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+	TODO: check
+CVE-2016-1836 (libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+	TODO: check
+CVE-2016-1835 (libxml2, as used in Apple iOS before 9.3.2 and OS X before 10.11.5, ...)
+	TODO: check
+CVE-2016-1834 (libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+	TODO: check
+CVE-2016-1833 (libxml2, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+	TODO: check
+CVE-2016-1832 (libc in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before ...)
+	TODO: check
+CVE-2016-1831 (The kernel in Apple iOS before 9.3.2 and OS X before 10.11.5 allows ...)
+	TODO: check
+CVE-2016-1830 (The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before ...)
+	TODO: check
+CVE-2016-1829 (The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before ...)
+	TODO: check
+CVE-2016-1828 (The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before ...)
+	TODO: check
+CVE-2016-1827 (The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before ...)
+	TODO: check
+CVE-2016-1826 (Integer overflow in the dtrace implementation in the kernel in Apple ...)
+	TODO: check
+CVE-2016-1825 (IOHIDFamily in Apple OS X before 10.11.5 allows attackers to execute ...)
+	TODO: check
+CVE-2016-1824 (IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+	TODO: check
+CVE-2016-1823 (IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+	TODO: check
+CVE-2016-1822 (IOFireWireFamily in Apple OS X before 10.11.5 allows attackers to ...)
+	TODO: check
+CVE-2016-1821 (IOAudioFamily in Apple OS X before 10.11.5 allows attackers to execute ...)
+	TODO: check
+CVE-2016-1820 (Buffer overflow in IOAudioFamily in Apple OS X before 10.11.5 allows ...)
+	TODO: check
+CVE-2016-1819 (IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, ...)
+	TODO: check
+CVE-2016-1818 (IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, ...)
+	TODO: check
+CVE-2016-1817 (IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, ...)
+	TODO: check
+CVE-2016-1816 (IOAcceleratorFamily in Apple OS X before 10.11.5 allows attackers to ...)
+	TODO: check
+CVE-2016-1815 (IOAcceleratorFamily in Apple OS X before 10.11.5 allows attackers to ...)
+	TODO: check
+CVE-2016-1814 (IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, ...)
+	TODO: check
+CVE-2016-1813 (IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, ...)
+	TODO: check
+CVE-2016-1812 (Buffer overflow in Intel Graphics Driver in Apple OS X before 10.11.5 ...)
+	TODO: check
+CVE-2016-1811 (ImageIO in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before ...)
+	TODO: check
+CVE-2016-1810 (The Graphics Drivers subsystem in Apple OS X before 10.11.5 allows ...)
+	TODO: check
+CVE-2016-1809 (Disk Utility in Apple OS X before 10.11.5 uses incorrect encryption ...)
+	TODO: check
+CVE-2016-1808 (The Disk Images subsystem in Apple iOS before 9.3.2, OS X before ...)
+	TODO: check
+CVE-2016-1807 (Race condition in the Disk Images subsystem in Apple iOS before 9.3.2, ...)
+	TODO: check
+CVE-2016-1806 (Crash Reporter in Apple OS X before 10.11.5 allows attackers to ...)
+	TODO: check
+CVE-2016-1805 (CoreStorage in Apple OS X before 10.11.5 allows attackers to execute ...)
+	TODO: check
+CVE-2016-1804 (The Multi-Touch subsystem in Apple OS X before 10.11.5 allows ...)
+	TODO: check
+CVE-2016-1803 (CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS ...)
+	TODO: check
+CVE-2016-1802 (CCCrypt in CommonCrypto in Apple iOS before 9.3.2, OS X before ...)
+	TODO: check
+CVE-2016-1801 (The CFNetwork Proxies subsystem in Apple iOS before 9.3.2, OS X before ...)
+	TODO: check
+CVE-2016-1800 (Captive Network Assistant in Apple OS X before 10.11.5 mishandles a ...)
+	TODO: check
+CVE-2016-1799 (Audio in Apple OS X before 10.11.5 allows attackers to execute ...)
+	TODO: check
+CVE-2016-1798 (Audio in Apple OS X before 10.11.5 allows attackers to cause a denial ...)
+	TODO: check
+CVE-2016-1797 (Apple Type Services (ATS) in Apple OS X before 10.11.5 allows ...)
+	TODO: check
+CVE-2016-1796 (Apple Type Services (ATS) in Apple OS X before 10.11.5 allows ...)
+	TODO: check
+CVE-2016-1795 (AppleGraphicsPowerManagement in Apple OS X before 10.11.5 allows ...)
+	TODO: check
+CVE-2016-1794 (AppleGraphicsControl in Apple OS X before 10.11.5 allows attackers to ...)
+	TODO: check
+CVE-2016-1793 (AppleGraphicsControl in Apple OS X before 10.11.5 allows attackers to ...)
+	TODO: check
+CVE-2016-1792 (The AMD subsystem in Apple OS X before 10.11.5 allows attackers to ...)
+	TODO: check
+CVE-2016-1791 (The AMD subsystem in Apple OS X before 10.11.5 allows attackers to ...)
+	TODO: check
+CVE-2016-1790 (Buffer overflow in the Accessibility component in Apple iOS before ...)
+	TODO: check
 CVE-2016-1789 (Apple iBooks Author before 2.4.1 allows remote attackers to read ...)
 	TODO: check
 CVE-2016-1788 (Messages in Apple iOS before 9.3, OS X before 10.11.4, and watchOS ...)
@@ -9395,8 +9390,8 @@
 	TODO: check
 CVE-2016-1743 (The Intel driver in the Graphics Drivers subsystem in Apple OS X ...)
 	TODO: check
-CVE-2016-1742
-	RESERVED
+CVE-2016-1742 (Untrusted search path vulnerability in the installer in Apple iTunes ...)
+	TODO: check
 CVE-2016-1741 (The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X ...)
 	TODO: check
 CVE-2016-1740 (FontParser in Apple iOS before 9.3, OS X before 10.11.4, tvOS before ...)




More information about the Secure-testing-commits mailing list