[Secure-testing-commits] r45065 - data/CVE

Nicholas Luedtke nluedtke-guest at moszumanska.debian.org
Wed Oct 5 16:01:59 UTC 2016


Author: nluedtke-guest
Date: 2016-10-05 16:01:59 +0000 (Wed, 05 Oct 2016)
New Revision: 45065

Modified:
   data/CVE/list
Log:
Add openjpeg2 to CVE-2016-515{2,7,8}

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-10-05 15:39:28 UTC (rev 45064)
+++ data/CVE/list	2016-10-05 16:01:59 UTC (rev 45065)
@@ -10451,12 +10451,17 @@
 	NOTE: https://github.com/uclouvain/openjpeg/commit/9a07ccb3d0f076388e4da684a3bfd4327125c721
 CVE-2016-5158 (Multiple integer overflows in the opj_tcd_init_tile function in tcd.c ...)
 	{DSA-3660-1}
+	- openjpeg2 <unfixed>
 	- chromium-browser 53.0.2785.89-1
 	[wheezy] - chromium-browser <end-of-life> (Not supported in Wheezy)
+	NOTE: https://github.com/uclouvain/openjpeg/issues/854
 CVE-2016-5157 (Heap-based buffer overflow in the opj_dwt_interleave_v function in ...)
 	{DSA-3660-1}
+	- openjpeg2 2.1.2-1
 	- chromium-browser 53.0.2785.89-1
 	[wheezy] - chromium-browser <end-of-life> (Not supported in Wheezy)
+	NOTE: http://www.openwall.com/lists/oss-security/2016/09/08/8
+	NOTE: https://github.com/uclouvain/openjpeg/pull/823
 CVE-2016-5156 (extensions/renderer/event_bindings.cc in the event bindings in Google ...)
 	{DSA-3660-1}
 	- chromium-browser 53.0.2785.89-1
@@ -10475,8 +10480,10 @@
 	[wheezy] - chromium-browser <end-of-life> (Not supported in Wheezy)
 CVE-2016-5152 (Integer overflow in the opj_tcd_get_decoded_tile_size function in ...)
 	{DSA-3660-1}
+	- openjpeg2 <unfixed>
 	- chromium-browser 53.0.2785.89-1
 	[wheezy] - chromium-browser <end-of-life> (Not supported in Wheezy)
+	NOTE: https://github.com/uclouvain/openjpeg/issues/854
 CVE-2016-5151 (PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and ...)
 	{DSA-3660-1}
 	- chromium-browser 53.0.2785.89-1




More information about the Secure-testing-commits mailing list