[Secure-testing-commits] r48214 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Fri Jan 20 05:55:59 UTC 2017


Author: carnil
Date: 2017-01-20 05:55:59 +0000 (Fri, 20 Jan 2017)
New Revision: 48214

Modified:
   data/CVE/list
Log:
Move bug #851161 to src:ruby2.1 (reassigned by maintiner)

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-01-20 05:19:13 UTC (rev 48213)
+++ data/CVE/list	2017-01-20 05:55:59 UTC (rev 48214)
@@ -36622,15 +36622,15 @@
 CVE-2016-2340 (The AMF framework in Granite Data Services 3.1.1-SNAPSHOT allows ...)
 	NOT-FOR-US: Granite
 CVE-2016-2339 (An exploitable heap overflow vulnerability exists in the ...)
-	- ruby2.3 <unfixed> (bug #851161)
-	- ruby2.1 <removed>
+	- ruby2.3 <unfixed>
+	- ruby2.1 <removed> (bug #851161)
 	NOTE: http://www.talosintelligence.com/reports/TALOS-2016-0034/
 	NOTE: Fixed by: https://github.com/ruby/ruby/commit/bcc2421b4938fc1d9f5f3fb6ef2320571b27af42
 CVE-2016-2338
 	RESERVED
 CVE-2016-2337 (Type confusion exists in _cancel_eval Ruby's TclTkIp class method. ...)
-	- ruby2.3 <unfixed> (bug #851161)
-	- ruby2.1 <removed>
+	- ruby2.3 <unfixed>
+	- ruby2.1 <removed> (bug #851161)
 	NOTE: http://www.talosintelligence.com/reports/TALOS-2016-0031/
 	TODO: check, might not be exploitable in jessie with ruby2.1, since requires cancel_eval which is supported in Tcl/Tk8.6 or later.
 CVE-2016-2336 (Type confusion exists in two methods of Ruby's WIN32OLE class, ...)




More information about the Secure-testing-commits mailing list