[Secure-testing-commits] r41949 - data/CVE
security tracker role
sectracker at moszumanska.debian.org
Mon May 23 09:10:15 UTC 2016
Author: sectracker
Date: 2016-05-23 09:10:15 +0000 (Mon, 23 May 2016)
New Revision: 41949
Modified:
data/CVE/list
Log:
automatic update
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2016-05-23 08:06:01 UTC (rev 41948)
+++ data/CVE/list 2016-05-23 09:10:15 UTC (rev 41949)
@@ -2140,6 +2140,7 @@
NOTE: https://github.com/roundcube/roundcubemail/commit/7bbefdb63b12e2344cf1cb87aeb6e3933b4063e0 (release-1.1)
NOTE: http://www.openwall.com/lists/oss-security/2016/04/23/3
CVE-2016-4085 (Stack-based buffer overflow in epan/dissectors/packet-ncp2222.inc in ...)
+ {DSA-3585-1}
- wireshark 2.0.0~rc2+g74e5b56-1
NOTE: https://www.wireshark.org/security/wnpa-sec-2016-28.html
NOTE: https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12293
@@ -2156,18 +2157,23 @@
[wheezy] - wireshark <not-affected> (Only affects 2.x)
NOTE: https://www.wireshark.org/security/wnpa-sec-2016-27.html
CVE-2016-4082 (epan/dissectors/packet-gsm_cbch.c in the GSM CBCH dissector in ...)
+ {DSA-3585-1}
- wireshark 2.0.3+geed34f0-1 (low)
NOTE: https://www.wireshark.org/security/wnpa-sec-2016-26.html
CVE-2016-4006 (epan/proto.c in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 ...)
+ {DSA-3585-1}
- wireshark 2.0.3+geed34f0-1 (low)
NOTE: https://www.wireshark.org/security/wnpa-sec-2016-25.html
CVE-2016-4081 (epan/dissectors/packet-iax2.c in the IAX2 dissector in Wireshark ...)
+ {DSA-3585-1}
- wireshark 2.0.3+geed34f0-1 (low)
NOTE: https://www.wireshark.org/security/wnpa-sec-2016-24.html
CVE-2016-4080 (epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark ...)
+ {DSA-3585-1}
- wireshark 2.0.3+geed34f0-1 (low)
NOTE: https://www.wireshark.org/security/wnpa-sec-2016-23.html
CVE-2016-4079 (epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark ...)
+ {DSA-3585-1}
- wireshark 2.0.3+geed34f0-1 (low)
NOTE: https://www.wireshark.org/security/wnpa-sec-2016-22.html
CVE-2016-4078 (The IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x ...)
@@ -3250,27 +3256,27 @@
CVE-2016-3719
REJECTED
CVE-2016-3718 (The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x ...)
- {DSA-3580-1 DLA-484-1}
+ {DSA-3580-1 DLA-486-1 DLA-484-1}
- imagemagick <unfixed>
- graphicsmagick <unfixed>
NOTE: https://sourceforge.net/p/graphicsmagick/mailman/message/35072963/
CVE-2016-3717 (The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 ...)
- {DSA-3580-1 DLA-484-1}
+ {DSA-3580-1 DLA-486-1 DLA-484-1}
- imagemagick <unfixed>
- graphicsmagick <unfixed>
NOTE: https://sourceforge.net/p/graphicsmagick/mailman/message/35072963/
CVE-2016-3716 (The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 ...)
- {DSA-3580-1 DLA-484-1}
+ {DSA-3580-1 DLA-486-1 DLA-484-1}
- imagemagick <unfixed>
- graphicsmagick <unfixed>
NOTE: https://sourceforge.net/p/graphicsmagick/mailman/message/35072963/
CVE-2016-3715 (The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before ...)
- {DSA-3580-1 DLA-484-1}
+ {DSA-3580-1 DLA-486-1 DLA-484-1}
- imagemagick <unfixed>
- graphicsmagick <unfixed>
NOTE: https://sourceforge.net/p/graphicsmagick/mailman/message/35072963/
CVE-2016-3714 (The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, ...)
- {DSA-3580-1 DLA-484-1}
+ {DSA-3580-1 DLA-486-1 DLA-484-1}
- imagemagick <unfixed>
NOTE: Workaround: https://bugzilla.redhat.com/show_bug.cgi?id=1332492#c3
NOTE: https://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=29588
More information about the Secure-testing-commits
mailing list