[Secure-testing-commits] r45064 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Wed Oct 5 15:39:28 UTC 2016


Author: carnil
Date: 2016-10-05 15:39:28 +0000 (Wed, 05 Oct 2016)
New Revision: 45064

Modified:
   data/CVE/list
Log:
Update status for CVE-2016-7907/qemu

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-10-05 15:34:07 UTC (rev 45063)
+++ data/CVE/list	2016-10-05 15:39:28 UTC (rev 45064)
@@ -1757,9 +1757,12 @@
 CVE-2016-7907 [net: inifinte loop in imx_fec_do_tx() function]
 	RESERVED
 	- qemu <unfixed>
-	- qemu-kvm <removed>
+	[jessie] - qemu <not-affected> (Vulnerable code introduced after v2.5.0-rc0)
+	[wheezy] - qemu <not-affected> (Vulnerable code introduced after v2.5.0-rc0)
+	- qemu-kvm <not-affected> (Vulnerable code introduced after v2.5.0-rc0)
 	NOTE: https://lists.gnu.org/archive/html/qemu-devel/2016-09/msg05556.html
-	TODO: check affected versions
+	NOTE: i.MX Fast Ethernet Controller emulation introduced in v2.5.0-rc0 with
+	NOTE: http://git.qemu.org/?p=qemu.git;a=commit;h=fcbd8018e645f3ab1ef9af94dc88a0d3272926d3 (v2.5.0-rc0)
 CVE-2016-7906
 	RESERVED
 	- imagemagick <unfixed>




More information about the Secure-testing-commits mailing list