[Secure-testing-commits] r46636 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Tue Nov 29 14:33:39 UTC 2016


Author: carnil
Date: 2016-11-29 14:33:39 +0000 (Tue, 29 Nov 2016)
New Revision: 46636

Modified:
   data/CVE/list
Log:
Add CVE-2016-9132/botan1.10

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-11-29 09:10:23 UTC (rev 46635)
+++ data/CVE/list	2016-11-29 14:33:39 UTC (rev 46636)
@@ -1818,8 +1818,11 @@
 	NOT-FOR-US: Exponent CMS
 CVE-2016-9133
 	RESERVED
-CVE-2016-9132
+CVE-2016-9132 [Integer overflow in BER decoder]
 	RESERVED
+	- botan1.10 <unfixed>
+	NOTE: Fixed in 1.10.14 and 1.11.34, all prior versions affected.
+	NOTE: Fixed by: https://github.com/randombit/botan/commit/987ad747db6d0d7e36f840398f3cf02e2fbfd90f
 CVE-2016-9131
 	RESERVED
 CVE-2016-9130




More information about the Secure-testing-commits mailing list