[Secure-testing-commits] r48080 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sun Jan 15 12:29:25 UTC 2017


Author: carnil
Date: 2017-01-15 12:29:25 +0000 (Sun, 15 Jan 2017)
New Revision: 48080

Modified:
   data/CVE/list
Log:
For the open php7.0 issues add as well php7.1 entry

Note: once details are more available for those CVE, rechecking is
needed. Still keep them for now at unfixed rather than undetermined,
since likely to affect 7.1.x as well for the version yet in unstable.

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-01-15 12:23:15 UTC (rev 48079)
+++ data/CVE/list	2017-01-15 12:29:25 UTC (rev 48080)
@@ -952,6 +952,7 @@
 	NOTE: Fixed by: http://git.savannah.gnu.org/cgit/icoutils.git/commit/?id=0d569f458f306b88f60156d60c9cf058125cf173
 	NOTE: http://www.openwall.com/lists/oss-security/2017/01/08/1
 CVE-2017-5340 (Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles ...)
+	- php7.1 <unfixed>
 	- php7.0 <unfixed> (bug #850158)
 	- php5 <removed>
 	NOTE: https://bugs.php.net/bug.php?id=73832
@@ -18971,10 +18972,12 @@
 	NOTE: PHP Bug: https://bugs.php.net/bug.php?id=73257
 	NOTE: Fixed in 7.0.12
 CVE-2016-7479 (In all versions of PHP 7, during the unserialization process, resizing ...)
+	- php7.1 <unfixed>
 	- php7.0 <unfixed>
 	- php5 <removed>
 	NOTE: PHP Bug: https://bugs.php.net/bug.php?id=73092
 CVE-2016-7478 (Zend/zend_exceptions.c in PHP, possibly 5.x before 5.6.28 and 7.x ...)
+	- php7.1 <unfixed>
 	- php7.0 <unfixed>
 	- php5 <removed>
 	NOTE: PHP Bug: https://bugs.php.net/bug.php?id=73093




More information about the Secure-testing-commits mailing list