[Secure-testing-commits] r53984 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Jul 27 11:05:47 UTC 2017


Author: carnil
Date: 2017-07-27 11:05:47 +0000 (Thu, 27 Jul 2017)
New Revision: 53984

Modified:
   data/CVE/list
Log:
Update information for CVE-2017-9610

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-07-27 10:01:31 UTC (rev 53983)
+++ data/CVE/list	2017-07-27 11:05:47 UTC (rev 53984)
@@ -5509,9 +5509,10 @@
 	NOTE: https://bugs.ghostscript.com/show_bug.cgi?id=698024
 	NOTE: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=c7c55972758a93350882c32147801a3485b010fe
 CVE-2017-9610 (The xps_load_sfnt_name function in xps/xpsfont.c in Artifex Ghostscript ...)
-	- ghostscript <unfixed>
+	- ghostscript <unfixed> (unimportant)
 	[jessie] - ghostscript <not-affected> (Vulnerable code not present)
 	[wheezy] - ghostscript <not-affected> (Vulnerable code not present)
+	NOTE: The Debian binary package is not affected xps/ not used
 	NOTE: https://bugs.ghostscript.com/show_bug.cgi?id=698025
 	NOTE: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=d2ab84732936b6e7e5a461dc94344902965e9a06
 CVE-2017-9609 (Cross-site scripting (XSS) vulnerability in Blackcat CMS 1.2 allows ...)




More information about the Secure-testing-commits mailing list