[Secure-testing-commits] r44669 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sat Sep 17 08:29:44 UTC 2016


Author: carnil
Date: 2016-09-17 08:29:44 +0000 (Sat, 17 Sep 2016)
New Revision: 44669

Modified:
   data/CVE/list
Log:
Add CVE-2016-7425/libav

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-09-17 08:23:18 UTC (rev 44668)
+++ data/CVE/list	2016-09-17 08:29:44 UTC (rev 44669)
@@ -2221,8 +2221,11 @@
 CVE-2016-7425 [SCSI arcmsr driver: buffer overflow in arcmsr_iop_message_xfer()]
 	RESERVED
 	- linux <unfixed>
-CVE-2016-7424
+CVE-2016-7424 [NULL pointer dereference in put_no_rnd_pixels8_xy2_mmx (rnd_template.c)]
 	RESERVED
+	- libav <removed>
+	NOTE: Fixed by: https://git.libav.org/?p=libav.git;a=commit;h=136f55207521f0b03194ef5b55ba70f1635d6aee
+	NOTE: https://blogs.gentoo.org/ago/2016/09/17/libav-null-pointer-dereference-in-put_no_rnd_pixels8_xy2_mmx-rnd_template-c/
 CVE-2016-7420 (Crypto++ (aka cryptopp) through 5.6.4 does not document the ...)
 	- libcrypto++ <unfixed>
 	[jessie] - libcrypto++ <no-dsa> (Minor issue)




More information about the Secure-testing-commits mailing list