[Secure-testing-commits] r47939 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Jan 12 07:22:58 UTC 2017


Author: carnil
Date: 2017-01-12 07:22:58 +0000 (Thu, 12 Jan 2017)
New Revision: 47939

Modified:
   data/CVE/list
Log:
mark CVE-2016-9587 as unfixed for now, add NOTE

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-01-12 06:44:46 UTC (rev 47938)
+++ data/CVE/list	2017-01-12 07:22:58 UTC (rev 47939)
@@ -11810,8 +11810,9 @@
 	NOTE: Fixed by: https://git.kernel.org/linus/ef85b67385436ddc1998f45f1d6a210f935b3388
 CVE-2016-9587 [Compromised remote hosts can lead to running commands on the Ansible controller]
 	RESERVED
-	- ansible 2.2.0.0-2 (bug #850846)
+	- ansible <unfixed> (bug #850846)
 	NOTE: Fixed by: https://github.com/ansible/ansible/commit/ec84ff6de6eca9224bf3f22b752bb8da806611ed (v2.2.1.0-0.3.rc3)
+	NOTE: Fixed in 2.2.0.0-2 only partially address the issues, need a follow-up.
 CVE-2016-9586 [printf floating point buffer overflow]
 	RESERVED
 	{DLA-767-1}




More information about the Secure-testing-commits mailing list