[Secure-testing-commits] r48410 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Jan 26 12:14:55 UTC 2017


Author: carnil
Date: 2017-01-26 12:14:55 +0000 (Thu, 26 Jan 2017)
New Revision: 48410

Modified:
   data/CVE/list
Log:
Add CVE-2016-6906/libgd2

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-01-26 11:23:00 UTC (rev 48409)
+++ data/CVE/list	2017-01-26 12:14:55 UTC (rev 48410)
@@ -21892,8 +21892,11 @@
 	RESERVED
 CVE-2016-6907
 	RESERVED
-CVE-2016-6906
+CVE-2016-6906 [OOB reads of the TGA decompression buffer]
 	RESERVED
+	- libgd2 <unfixed>
+	NOTE: Fixed by: https://github.com/libgd/libgd/commit/fb0e0cce0b9f25389ab56604c3547351617e1415
+	NOTE: Fixed by: https://github.com/libgd/libgd/commit/58b6dde319c301b0eae27d12e2a659e067d80558
 CVE-2016-6904
 	RESERVED
 CVE-2016-6901 (Format string vulnerability in Huawei AR100, AR120, AR150, AR200, ...)




More information about the Secure-testing-commits mailing list