[Secure-testing-commits] r51154 - in data: . CVE

Moritz Muehlenhoff jmm at moszumanska.debian.org
Fri Apr 28 17:38:23 UTC 2017


Author: jmm
Date: 2017-04-28 17:38:23 +0000 (Fri, 28 Apr 2017)
New Revision: 51154

Modified:
   data/CVE/list
   data/next-point-update.txt
Log:
activemq spu


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-04-28 17:36:31 UTC (rev 51153)
+++ data/CVE/list	2017-04-28 17:38:23 UTC (rev 51154)
@@ -63225,11 +63225,12 @@
 CVE-2015-5180 [DNS resolver NULL pointer dereference with crafted record type]
 	RESERVED
 	- glibc 2.24-9 (low; bug #796106)
-	[jessie] - glibc <no-dsa> (Minor issue)
+	[jessie] - glibc <no-dsa> (Minor issue, too intrusive to backport)
 	- eglibc <removed> (low)
 	[wheezy] - eglibc <no-dsa> (Minor issue)
 	[squeeze] - eglibc <no-dsa> (Minor issue)
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=18784
+	NOTE: Originally proposed for jessie 8.8, but breaks the NSS ABI so was retracted
 CVE-2015-5179 [non-printable characters aren't check in every case of user data]
 	RESERVED
 	- freeipa <unfixed> (bug #795399)

Modified: data/next-point-update.txt
===================================================================
--- data/next-point-update.txt	2017-04-28 17:36:31 UTC (rev 51153)
+++ data/next-point-update.txt	2017-04-28 17:38:23 UTC (rev 51154)
@@ -164,3 +164,5 @@
 	[jessie] - spip 3.0.17-2+deb8u3
 CVE-2016-9998
 	[jessie] - spip 3.0.17-2+deb8u3
+CVE-2015-7559
+	[jessie] - activemq 5.6.0+dfsg1-4+deb8u3




More information about the Secure-testing-commits mailing list