[Secure-testing-commits] r47927 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Wed Jan 11 21:22:13 UTC 2017


Author: carnil
Date: 2017-01-11 21:22:13 +0000 (Wed, 11 Jan 2017)
New Revision: 47927

Modified:
   data/CVE/list
Log:
Update CVE-2016-9778, mark for now as undetermined

Not all versions of bind support the nxdomain-redirect feature. Need
investigation which version is affected if.

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-01-11 21:16:39 UTC (rev 47926)
+++ data/CVE/list	2017-01-11 21:22:13 UTC (rev 47927)
@@ -5924,9 +5924,7 @@
 	RESERVED
 CVE-2016-9778 [An error handling certain queries using the nxdomain-redirect feature could cause a REQUIRE assertion failure in db.c]
 	RESERVED
-	- bind9 <unfixed>
-	[jessie] - bind9 <not-affected> (Vulnerable code introduced later)
-	[wheezy] - bind9 <not-affected> (Vulnerable code introduced later)
+	- bind9 <undetermined>
 	NOTE: https://kb.isc.org/article/AA-01442/0
 CVE-2016-9771
 	RESERVED




More information about the Secure-testing-commits mailing list