[Secure-testing-commits] r44415 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Sep 8 12:11:42 UTC 2016


Author: carnil
Date: 2016-09-08 12:11:42 +0000 (Thu, 08 Sep 2016)
New Revision: 44415

Modified:
   data/CVE/list
Log:
Add CVE-2016-7154/xen

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-09-08 12:09:41 UTC (rev 44414)
+++ data/CVE/list	2016-09-08 12:11:42 UTC (rev 44415)
@@ -5,6 +5,11 @@
 	NOTE: https://github.com/ADOdb/ADOdb/issues/226
 	NOTE: https://github.com/ADOdb/ADOdb/commit/bd9eca9
 	NOTE: CVE Request: http://www.openwall.com/lists/oss-security/2016/09/07/8
+CVE-2016-7154 [use after free in FIFO event channel code]
+	- xen 4.6.0-1
+	NOTE: http://xenbits.xen.org/xsa/advisory-188.html
+	NOTE: Only affects Xen 4.4, as workaround it is marked as fixed in the first xen version entering unstable
+	NOTE: after the 4.4 series.
 CVE-2016-7164 [inflate_gzip denial of service]
 	- libtorrent-rasterbar <unfixed>
 	NOTE: https://github.com/arvidn/libtorrent/issues/1021




More information about the Secure-testing-commits mailing list