[Secure-testing-commits] r45424 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Tue Oct 18 14:48:36 UTC 2016


Author: carnil
Date: 2016-10-18 14:48:36 +0000 (Tue, 18 Oct 2016)
New Revision: 45424

Modified:
   data/CVE/list
Log:
Add new php7.0/php5 issue

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-10-18 14:00:40 UTC (rev 45423)
+++ data/CVE/list	2016-10-18 14:48:36 UTC (rev 45424)
@@ -5,6 +5,13 @@
 	NOTE: https://trac.torproject.org/projects/tor/ticket/20384
 	NOTE: https://blog.torproject.org/blog/tor-0289-released-important-fixes
 	NOTE: https://github.com/torproject/tor/commit/3cea86eb2fbb65949673eb4ba8ebb695c87a57ce
+CVE-2016-XXXX [Use After Free in unserialize()]
+	- php7.0 7.0.12-1
+	- php5 <unfixed>
+	NOTE: PHP Bug: https://bugs.php.net/bug.php?id=73147
+	NOTE: http://git.php.net/?p=php-src.git;a=commit;h=0e6fe3a4c96be2d3e88389a5776f878021b4c59f
+	NOTE: NOTE: Fixed in 7.0.12, 5.6.27
+	NOTE: CVE Request: www.openwall.com/lists/oss-security/2016/10/18/1
 CVE-2016-8673
 	RESERVED
 CVE-2016-8672




More information about the Secure-testing-commits mailing list