[Secure-testing-commits] r44312 - data/CVE

Markus Koschany apo at moszumanska.debian.org
Sun Sep 4 19:03:59 UTC 2016


Author: apo
Date: 2016-09-04 19:03:59 +0000 (Sun, 04 Sep 2016)
New Revision: 44312

Modified:
   data/CVE/list
Log:
CVE-2010-2596: fixed in Stretch

Add link to patch for Wheezy and Jessie


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-09-04 17:04:50 UTC (rev 44311)
+++ data/CVE/list	2016-09-04 19:03:59 UTC (rev 44312)
@@ -131588,9 +131588,9 @@
 	- tiff3 3.9.6-1
 	NOTE: may have been fixed earlier
 CVE-2010-2596 (The OJPEGPostDecode function in tif_ojpeg.c in LibTIFF 3.9.0 and ...)
-	- tiff <unfixed> (unimportant)
+	- tiff 4.0.6
 	- tiff3 <unfixed> (unimportant)
-	NOTE: no fix available as of July 2013
+	NOTE: fixed by http://bugzilla.maptools.org/show_bug.cgi?id=2209
 CVE-2010-2595 (The TIFFYCbCrtoRGB function in LibTIFF 3.9.0 and 3.9.2, as used in ...)
 	{DSA-2552-1}
 	- tiff 3.9.6-1




More information about the Secure-testing-commits mailing list