[Secure-testing-commits] r45703 - data/CVE
Raphaël Hertzog
hertzog at moszumanska.debian.org
Fri Oct 28 12:50:24 UTC 2016
Author: hertzog
Date: 2016-10-28 12:50:24 +0000 (Fri, 28 Oct 2016)
New Revision: 45703
Modified:
data/CVE/list
Log:
CVE-2015-8668/tiff3: update status in wheezy to not-affected
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2016-10-28 12:50:14 UTC (rev 45702)
+++ data/CVE/list 2016-10-28 12:50:24 UTC (rev 45703)
@@ -25943,7 +25943,7 @@
CVE-2015-8668 (Heap-based buffer overflow in the PackBitsPreEncode function in ...)
- tiff <unfixed> (bug #842046)
- tiff3 <removed>
- [wheezy] - tiff3 <no-dsa> (Issue is in bmp2tiff but we don't ship tools, tools are shipped by "tiff")
+ [wheezy] - tiff3 <not-affected> (Does not ship libtiff tools)
NOTE: http://bugzilla.maptools.org/show_bug.cgi?id=2563
NOTE: Red Hat say it's only OOB read: https://bugzilla.redhat.com/show_bug.cgi?id=1294425#c1
NOTE: Red Hat's patch is partially incorrect according to upstream
More information about the Secure-testing-commits
mailing list