[Secure-testing-commits] r53164 - data/CVE

Moritz Muehlenhoff jmm at moszumanska.debian.org
Tue Jul 4 11:40:46 UTC 2017


Author: jmm
Date: 2017-07-04 11:40:46 +0000 (Tue, 04 Jul 2017)
New Revision: 53164

Modified:
   data/CVE/list
Log:
new libav issue (ffmpeg fixed)
Android NFUs


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-07-04 10:15:42 UTC (rev 53163)
+++ data/CVE/list	2017-07-04 11:40:46 UTC (rev 53164)
@@ -27861,38 +27861,38 @@
 CVE-2017-0652
 	RESERVED
 CVE-2017-0651 (An information disclosure vulnerability in the kernel ION subsystem ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2017-0650 (An information disclosure vulnerability in the Synaptics touchscreen ...)
-	TODO: check
+	NOT-FOR-US: Synaptics driver for Android
 CVE-2017-0649 (An elevation of privilege vulnerability in the MediaTek sound driver ...)
-	TODO: check
+	NOT-FOR-US: MediaTek driver for Android
 CVE-2017-0648 (An elevation of privilege vulnerability in the kernel FIQ debugger ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2017-0647 (An information disclosure vulnerability in libziparchive could enable ...)
 	- android-platform-system-core <unfixed>
 CVE-2017-0646 (An information disclosure vulnerability in Bluetooth component could ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2017-0645 (An elevation of privilege vulnerability in Bluetooth could enable a ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2017-0644 (A remote denial of service vulnerability in Mediaserver could enable ...)
-	TODO: check
+	NOT-FOR-US: Android Mediaserver
 CVE-2017-0643 (A remote denial of service vulnerability in Mediaserver could enable ...)
-	TODO: check
+	NOT-FOR-US: Android Mediaserver
 CVE-2017-0642 (A remote denial of service vulnerability in libhevc in Mediaserver ...)
-	TODO: check
+	NOT-FOR-US: Android Mediaserver
 CVE-2017-0641 (A remote denial of service vulnerability in libvpx in Mediaserver ...)
 	- libvpx <undetermined>
 	TODO: check
 CVE-2017-0640 (A remote denial of service vulnerability in Mediaserver could enable ...)
-	TODO: check
+	NOT-FOR-US: Android Mediaserver
 CVE-2017-0639 (An information disclosure vulnerability in Bluetooth component could ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2017-0638 (A remote code execution vulnerability in System UI component could ...)
-	TODO: check
+	NOT-FOR-US: Android
 CVE-2017-0637 (A remote code execution vulnerability in libhevc in Mediaserver could ...)
-	TODO: check
+	NOT-FOR-US: Android Mediaserver
 CVE-2017-0636 (An elevation of privilege vulnerability in the MediaTek command queue ...)
-	TODO: check
+	NOT-FOR-US: MediaTek driver for Android
 CVE-2017-0635 (A remote denial of service vulnerability in HevcUtils.cpp in ...)
 	NOT-FOR-US: libstagefright
 CVE-2017-0634 (An information disclosure vulnerability in the Synaptics touchscreen ...)
@@ -82709,7 +82709,9 @@
 CVE-2015-1208
 	RESERVED
 CVE-2015-1207 (Double-free vulnerability in libavformat/mov.c in FFMPEG in Google ...)
-	TODO: check
+	- ffmpeg 7:2.6.1-1
+	- libav <removed>
+	NOTE: http://git.videolan.org/?p=ffmpeg.git;a=commit;h=3859868c75313e318ebc5d0d33baada62d45dd75
 CVE-2015-1206
 	RESERVED
 CVE-2015-1204 (Cross-site scripting (XSS) vulnerability in the Save Filters ...)




More information about the Secure-testing-commits mailing list