[Secure-testing-commits] r53987 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Jul 27 11:13:53 UTC 2017


Author: carnil
Date: 2017-07-27 11:13:53 +0000 (Thu, 27 Jul 2017)
New Revision: 53987

Modified:
   data/CVE/list
Log:
Update CVE-2017-9620

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-07-27 11:12:08 UTC (rev 53986)
+++ data/CVE/list	2017-07-27 11:13:53 UTC (rev 53987)
@@ -5477,7 +5477,10 @@
 CVE-2017-9621 (Cross-site scripting (XSS) vulnerability in ...)
 	NOT-FOR-US: Telaxus/EPESI
 CVE-2017-9620 (The xps_select_font_encoding function in xps/xpsfont.c in Artifex ...)
-	- ghostscript <unfixed>
+	- ghostscript <unfixed> (unimportant)
+	[jessie] - ghostscript <not-affected> (Vulnerable code not present)
+	[wheezy] - ghostscript <not-affected> (Vulnerable code not present)
+	NOTE: The Debian binary package is not affected xps/ not used
 	NOTE: https://bugs.ghostscript.com/show_bug.cgi?id=698050
 	NOTE: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=3ee55637480d5e319a5de0481b01c3346855cbc9
 CVE-2017-9619 (The xps_true_callback_glyph_name function in xps/xpsttf.c in Artifex ...)




More information about the Secure-testing-commits mailing list