[Secure-testing-commits] r58540 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Wed Dec 13 21:24:36 UTC 2017


Author: carnil
Date: 2017-12-13 21:24:35 +0000 (Wed, 13 Dec 2017)
New Revision: 58540

Modified:
   data/CVE/list
Log:
Add CVE-2017-17524/swi-prolog

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-12-13 21:21:08 UTC (rev 58539)
+++ data/CVE/list	2017-12-13 21:24:35 UTC (rev 58540)
@@ -340,8 +340,10 @@
 	RESERVED
 CVE-2017-17525
 	RESERVED
-CVE-2017-17524
+CVE-2017-17524 [argument injection]
 	RESERVED
+	- swi-prolog <unfixed>
+	NOTE: https://sources.debian.org/src/swi-prolog/7.2.3+dfsg-1/library/www_browser.pl/?hl=68#L68
 CVE-2017-17523 (lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings ...)
 	- lilypond <unfixed> (bug #884136)
 	[jessie] - lilypond <no-dsa> (Minor issue)




More information about the Secure-testing-commits mailing list