[Secure-testing-commits] r48513 - data/CVE
Salvatore Bonaccorso
carnil at moszumanska.debian.org
Sun Jan 29 10:11:26 UTC 2017
Author: carnil
Date: 2017-01-29 10:11:26 +0000 (Sun, 29 Jan 2017)
New Revision: 48513
Modified:
data/CVE/list
Log:
Add upstream issue for CVE-2017-5499
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2017-01-29 10:05:11 UTC (rev 48512)
+++ data/CVE/list 2017-01-29 10:11:26 UTC (rev 48513)
@@ -879,6 +879,7 @@
- jasper <removed> (unimportant)
NOTE: Reproducer: https://github.com/asarubbo/poc/blob/master/00018-jasper-signedintoverflow-jpc_dec_c
NOTE: http://blogs.gentoo.org/ago/2017/01/16/jasper-multiple-crashes-with-ubsan/
+ NOTE: https://github.com/mdadams/jasper/issues/63
NOTE: Triggers an assert. Not suitable for code injection, hardly denial of service
CVE-2017-5498
RESERVED
More information about the Secure-testing-commits
mailing list