[Secure-testing-commits] r46140 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sat Nov 12 06:10:29 UTC 2016


Author: carnil
Date: 2016-11-12 06:10:28 +0000 (Sat, 12 Nov 2016)
New Revision: 46140

Modified:
   data/CVE/list
Log:
Add TODO for CVE-2016-9085

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-11-12 05:41:55 UTC (rev 46139)
+++ data/CVE/list	2016-11-12 06:10:28 UTC (rev 46140)
@@ -651,7 +651,7 @@
 	NOTE: Report: https://bugs.chromium.org/p/webp/issues/detail?id=314 (private)
 	NOTE: For libwebp only in examples, but other projects seem to use the gifdec.c
 	NOTE: Origin of the file seems to be from libav
-	TODO: check other projects
+	TODO: check: 0.5.1-3 claims the upload fixed CVE-2016-8888 and CVE-2016-9085 but the taken patch looks different, needs investigation
 CVE-2016-9084 [... "kzalloc is changed to a kcalloc."]
 	RESERVED
 	- linux <unfixed>




More information about the Secure-testing-commits mailing list