[Secure-testing-commits] r50812 - data/CVE

Moritz Muehlenhoff jmm at moszumanska.debian.org
Wed Apr 19 22:00:03 UTC 2017


Author: jmm
Date: 2017-04-19 22:00:03 +0000 (Wed, 19 Apr 2017)
New Revision: 50812

Modified:
   data/CVE/list
Log:
new libcroco, jbig2dec issues
NFUs


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-04-19 21:10:12 UTC (rev 50811)
+++ data/CVE/list	2017-04-19 22:00:03 UTC (rev 50812)
@@ -1,9 +1,9 @@
 CVE-2017-7977
 	RESERVED
 CVE-2017-7976 (Artifex jbig2dec 0.13 allows out-of-bounds writes and reads because of ...)
-	TODO: check
+	- jbig2dec <unfixed>
 CVE-2017-7975 (Artifex jbig2dec 0.13, as used in Ghostscript, allows out-of-bounds ...)
-	TODO: check
+	- jbig2dec <unfixed>
 CVE-2017-7974
 	RESERVED
 CVE-2017-7973
@@ -25,15 +25,15 @@
 CVE-2017-7965
 	RESERVED
 CVE-2017-7964 (Zyxel WRE6505 devices have a default TELNET password of 1234 for the ...)
-	TODO: check
+	NOT-FOR-US: Zyxel
 CVE-2017-7963 (** DISPUTED ** The GNU Multiple Precision Arithmetic Library (GMP) ...)
 	TODO: check
 CVE-2017-7962 (The iwgif_read_image function in imagew-gif.c in libimageworsener.a in ...)
-	TODO: check
+	NOT-FOR-US: ImageWorsener
 CVE-2017-7961 (The cr_tknzr_parse_rgb function in cr-tknzr.c in libcroco 0.6.11 and ...)
-	TODO: check
+	- libcroco <unfixed>
 CVE-2017-7960 (The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and ...)
-	TODO: check
+	- libcroco <unfixed>
 CVE-2017-7959
 	RESERVED
 CVE-2017-7958




More information about the Secure-testing-commits mailing list