[Secure-testing-commits] r50310 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Tue Apr 4 04:31:12 UTC 2017


Author: carnil
Date: 2017-04-04 04:31:12 +0000 (Tue, 04 Apr 2017)
New Revision: 50310

Modified:
   data/CVE/list
Log:
Add CVE-2017-0360/tryton-server

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-04-03 19:34:18 UTC (rev 50309)
+++ data/CVE/list	2017-04-04 04:31:12 UTC (rev 50310)
@@ -18487,8 +18487,10 @@
 	RESERVED
 CVE-2017-0361
 	RESERVED
-CVE-2017-0360
+CVE-2017-0360 [Sanitize path in file_open against suffix]
 	RESERVED
+	- tryton-server <unfixed>
+	NOTE: Fixed by: http://hg.tryton.org/trytond?cmd=changeset;node=472510fdc6f8 (4.2.x)
 CVE-2017-0359 [diffoscope writes to arbitrary locations on disk based on the contents of an untrusted archive]
 	RESERVED
 	- diffoscope 76 (bug #854723)




More information about the Secure-testing-commits mailing list