[Secure-testing-commits] r48768 - data/CVE

Sebastien Delafond seb at moszumanska.debian.org
Wed Feb 8 09:32:08 UTC 2017


Author: seb
Date: 2017-02-08 09:32:08 +0000 (Wed, 08 Feb 2017)
New Revision: 48768

Modified:
   data/CVE/list
Log:
Add temporary entry for openpyxl XXE

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-02-08 09:26:21 UTC (rev 48767)
+++ data/CVE/list	2017-02-08 09:32:08 UTC (rev 48768)
@@ -139,6 +139,9 @@
 	NOTE: https://bugzilla.suse.com/show_bug.cgi?id=1023012
 CVE-2016-10200
 	RESERVED
+CVE-2017-XXXX [openpyxl XML External Entity (XXE) vulnerability]
+	- openpyxl <unfixed> (bug #854442)
+	NOTE: CVE request at http://www.openwall.com/lists/oss-security/2017/02/07/5
 CVE-2017-XXXX [gnome-keyring lives on after ssh session stops]
 	- gnome-keyring <unfixed> (low; bug #395572)
 	[jessie] - gnome-keyring <no-dsa> (Minor issue)




More information about the Secure-testing-commits mailing list