[Secure-testing-commits] r44304 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sun Sep 4 12:12:31 UTC 2016


Author: carnil
Date: 2016-09-04 12:12:31 +0000 (Sun, 04 Sep 2016)
New Revision: 44304

Modified:
   data/CVE/list
Log:
Cleanup entry for CVE-2016-7118 after DLA-609-1 release

Otherwise the explicitly tagged [wheezy], unfixed entry will overwrite
the setting from the DLA. This is not needed anymore as workaround since
now fixed.

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-09-04 11:51:46 UTC (rev 44303)
+++ data/CVE/list	2016-09-04 12:12:31 UTC (rev 44304)
@@ -115,11 +115,8 @@
 CVE-2016-7118 (fs/fcntl.c in the "aufs 3.2.x+setfl-debian" patch in the linux-image ...)
 	{DLA-609-1}
 	- linux <not-affected>
-	[wheezy] - linux <unfixed>
 	NOTE: Bit of complicated tracking information. For jessie the affected version is not in any yet
-	NOTE: released version, thus should be n/a. wheezy OTOH, has already the issue in a released version,
-	NOTE: workaround the tracking problem by explicitly marking the wheezy version as unfixed and the
-	NOTE: other upper suites as not-affected.
+	NOTE: released version, thus should be n/a. wheezy OTOH, has already the issue in a released version. Issue then was fixed in 3.2.81-2 in DLA-609-1
 	NOTE: http://www.openwall.com/lists/oss-security/2016/08/31/1
 CVE-2016-7116 [9p: directory traversal flaw in 9p virtio backend]
 	RESERVED




More information about the Secure-testing-commits mailing list