[Secure-testing-commits] r48371 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Wed Jan 25 12:24:37 UTC 2017


Author: carnil
Date: 2017-01-25 12:24:37 +0000 (Wed, 25 Jan 2017)
New Revision: 48371

Modified:
   data/CVE/list
Log:
Add CVE-2016-10161/php

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-01-25 12:22:52 UTC (rev 48370)
+++ data/CVE/list	2017-01-25 12:24:37 UTC (rev 48371)
@@ -158,6 +158,12 @@
 	RESERVED
 CVE-2017-5527
 	RESERVED
+CVE-2016-10161 [Heap out of bounds read on unserialize in finish_nested_data()]
+	- php7.1 <unfixed>
+	- php7.0 7.0.15-1
+	- php5 <removed>
+	NOTE: PHP Bug: http://bugs.php.net/73825
+	NOTE: Fixed in 5.6.30, 7.0.15, 7.1.1
 CVE-2016-10160 [Memory corruption when loading hostile phar]
 	- php7.1 <unfixed>
 	- php7.0 7.0.15-1




More information about the Secure-testing-commits mailing list