[Secure-testing-commits] r53954 - in data: . CVE
Emilio Pozuelo Monfort
pochu at moszumanska.debian.org
Wed Jul 26 17:39:21 UTC 2017
Author: pochu
Date: 2017-07-26 17:39:21 +0000 (Wed, 26 Jul 2017)
New Revision: 53954
Modified:
data/CVE/list
data/dla-needed.txt
Log:
mark ncurses as no-dsa on wheezy
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2017-07-26 16:01:52 UTC (rev 53953)
+++ data/CVE/list 2017-07-26 17:39:21 UTC (rev 53954)
@@ -1636,11 +1636,13 @@
- ncurses 6.0+20170701-1
[stretch] - ncurses <no-dsa> (Minor issue)
[jessie] - ncurses <no-dsa> (Minor issue)
+ [wheezy] - ncurses <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1464691
CVE-2017-11112 (In ncurses 6.0, there is an attempted 0xffffffffffffffff access in the ...)
- ncurses 6.0+20170701-1
[stretch] - ncurses <no-dsa> (Minor issue)
[jessie] - ncurses <no-dsa> (Minor issue)
+ [wheezy] - ncurses <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1464686
CVE-2017-11111 (In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers ...)
- nasm <unfixed> (bug #867988)
@@ -2709,11 +2711,13 @@
- ncurses 6.0+20170701-1
[stretch] - ncurses <no-dsa> (Minor issue)
[jessie] - ncurses <no-dsa> (Minor issue)
+ [wheezy] - ncurses <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1464692
CVE-2017-10684 (In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry ...)
- ncurses 6.0+20170708-1
[stretch] - ncurses <no-dsa> (Minor issue)
[jessie] - ncurses <no-dsa> (Minor issue)
+ [wheezy] - ncurses <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1464687
CVE-2017-10683 (In mpg123 1.25.0, there is a heap-based buffer over-read in the ...)
{DLA-1017-1}
Modified: data/dla-needed.txt
===================================================================
--- data/dla-needed.txt 2017-07-26 16:01:52 UTC (rev 53953)
+++ data/dla-needed.txt 2017-07-26 17:39:21 UTC (rev 53954)
@@ -125,8 +125,6 @@
--
nasm (Thorsten Alteholz)
--
-ncurses (Emilio Pozuelo)
---
openexr
NOTE: 20170707: Pinged upstream (lamby)
--
More information about the Secure-testing-commits
mailing list