[Secure-testing-commits] r44798 - data/CVE
Salvatore Bonaccorso
carnil at moszumanska.debian.org
Wed Sep 21 17:48:55 UTC 2016
Author: carnil
Date: 2016-09-21 17:48:55 +0000 (Wed, 21 Sep 2016)
New Revision: 44798
Modified:
data/CVE/list
Log:
Reorganize information for CVE-2016-5418
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2016-09-21 17:46:35 UTC (rev 44797)
+++ data/CVE/list 2016-09-21 17:48:55 UTC (rev 44798)
@@ -8649,13 +8649,13 @@
- libarchive <unfixed> (bug #837714)
NOTE: Centos patch: https://git.centos.org/blob/rpms!libarchive.git/9952851f8b327a8c93d26a5873c190c1fb09ae6c/SOURCES!libarchive-3.1.2-CVE-2016-5418.patch;jsessionid=1dexz8h9qdewibih5aonbu3
NOTE: Centos additional patch: https://git.centos.org/blob/rpms!libarchive.git/9952851f8b327a8c93d26a5873c190c1fb09ae6c/SOURCES!libarchive-3.1.2-CVE-2016-5418-variation.patch;jsessionid=1dexz8h9qdewibih5aonbu3
- NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/dfd6b54ce33960e420fb206d8872fb759b577ad9
+ NOTE: Fixed by (for #744): https://github.com/libarchive/libarchive/commit/1fa9c7bf90f0862036a99896b0501c381584451a
+ NOTE: Fixed by (for #745 and #746): https://github.com/libarchive/libarchive/commit/dfd6b54ce33960e420fb206d8872fb759b577ad9
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1362601, relates to upstream bugs #744, #745 and #746
NOTE: https://github.com/libarchive/libarchive/issues/743 (umbrella report)
NOTE: https://github.com/libarchive/libarchive/issues/744
NOTE: https://github.com/libarchive/libarchive/issues/745
NOTE: https://github.com/libarchive/libarchive/issues/746
- NOTE: Upstream bugs closed with: https://github.com/libarchive/libarchive/commit/1fa9c7bf90f0862036a99896b0501c381584451a and https://github.com/libarchive/libarchive/commit/dfd6b54ce33960e420fb206d8872fb759b577ad9
TODO: still need to check details about the CVE, cf. comments in Red Hat bugzilla, Salvatore contacted Red Hat
CVE-2016-5417 [per-thread memory leak in __res_vinit with IPv6 nameservers]
RESERVED
More information about the Secure-testing-commits
mailing list