[Secure-testing-commits] r44313 - data/CVE

Markus Koschany apo at moszumanska.debian.org
Sun Sep 4 19:08:35 UTC 2016


Author: apo
Date: 2016-09-04 19:08:34 +0000 (Sun, 04 Sep 2016)
New Revision: 44313

Modified:
   data/CVE/list
Log:
CVE-2013-1961 will be fixed in Wheezy (tiff3)


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-09-04 19:03:59 UTC (rev 44312)
+++ data/CVE/list	2016-09-04 19:08:34 UTC (rev 44313)
@@ -88006,7 +88006,6 @@
 	{DSA-2698-1}
 	- tiff 4.0.2-6+nmu1 (bug #706674)
 	- tiff3 3.9.7-1 (bug #712840)
-	[wheezy] - tiff3 <no-dsa> (the changes that effect the library are just hardening, converting uses of sprintf to snprintf. those can be rolled into the next tiff3 update, but a separate dsa isn't needed)
 CVE-2013-1960 (Heap-based buffer overflow in the t2p_process_jpeg_strip function in ...)
 	{DSA-2698-1}
 	- tiff 4.0.2-6+nmu1 (bug #706675)




More information about the Secure-testing-commits mailing list