[Secure-testing-commits] r48513 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sun Jan 29 10:11:26 UTC 2017


Author: carnil
Date: 2017-01-29 10:11:26 +0000 (Sun, 29 Jan 2017)
New Revision: 48513

Modified:
   data/CVE/list
Log:
Add upstream issue for CVE-2017-5499

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-01-29 10:05:11 UTC (rev 48512)
+++ data/CVE/list	2017-01-29 10:11:26 UTC (rev 48513)
@@ -879,6 +879,7 @@
 	- jasper <removed> (unimportant)
 	NOTE: Reproducer: https://github.com/asarubbo/poc/blob/master/00018-jasper-signedintoverflow-jpc_dec_c
 	NOTE: http://blogs.gentoo.org/ago/2017/01/16/jasper-multiple-crashes-with-ubsan/
+	NOTE: https://github.com/mdadams/jasper/issues/63
 	NOTE: Triggers an assert. Not suitable for code injection, hardly denial of service
 CVE-2017-5498
 	RESERVED




More information about the Secure-testing-commits mailing list