[Secure-testing-commits] r45686 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Fri Oct 28 05:21:23 UTC 2016


Author: carnil
Date: 2016-10-28 05:21:23 +0000 (Fri, 28 Oct 2016)
New Revision: 45686

Modified:
   data/CVE/list
Log:
Add CVE-2016-7076/sudo

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-10-28 05:13:26 UTC (rev 45685)
+++ data/CVE/list	2016-10-28 05:21:23 UTC (rev 45686)
@@ -5824,8 +5824,11 @@
 	RESERVED
 	- foreman <itp> (bug #663101)
 	NOTE: http://projects.theforeman.org/issues/16971
-CVE-2016-7076
+CVE-2016-7076 [noexec bypass via wordexp()]
 	RESERVED
+	- sudo <unfixed>
+	NOTE: https://www.sudo.ws/alerts/noexec_wordexp.html
+	NOTE: The CVE id on upstream advisory is wrong, should be CVE-2016-7076.
 CVE-2016-7075
 	RESERVED
 	- kubernetes <itp> (bug #795652)




More information about the Secure-testing-commits mailing list