[Secure-testing-commits] r45176 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Mon Oct 10 08:17:09 UTC 2016


Author: carnil
Date: 2016-10-10 08:17:08 +0000 (Mon, 10 Oct 2016)
New Revision: 45176

Modified:
   data/CVE/list
Log:
Add CVE-2016-5425

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-10-10 06:44:13 UTC (rev 45175)
+++ data/CVE/list	2016-10-10 08:17:08 UTC (rev 45176)
@@ -9440,6 +9440,10 @@
 	NOTE: https://github.com/PowerDNS/pdns/commit/881b5b03a590198d03008e4200dd00cc537712f3
 CVE-2016-5425
 	RESERVED
+	- tomcat8 <not-affected> (Red Hat and derivatives packaging specific)
+	- tomcat7 <not-affected> (Red Hat and derivatives packaging specific)
+	- tomcat6 <not-affected> (Red Hat and derivatives packaging specific)
+	NOTE: http://legalhackers.com/advisories/Tomcat-RedHat-Pkgs-Root-PrivEsc-Exploit-CVE-2016-5425.html
 CVE-2016-5424 [Fix client programs' handling of special characters in database and role names]
 	RESERVED
 	{DSA-3646-1 DLA-592-1}




More information about the Secure-testing-commits mailing list