[Secure-testing-commits] r52383 - data/CVE
Salvatore Bonaccorso
carnil at moszumanska.debian.org
Wed Jun 7 12:05:54 UTC 2017
Author: carnil
Date: 2017-06-07 12:05:54 +0000 (Wed, 07 Jun 2017)
New Revision: 52383
Modified:
data/CVE/list
Log:
Track upstream issue for CVE-2017-9474/libytnef
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2017-06-07 11:22:07 UTC (rev 52382)
+++ data/CVE/list 2017-06-07 12:05:54 UTC (rev 52383)
@@ -47,7 +47,9 @@
CVE-2017-9475
RESERVED
CVE-2017-9474 (In ytnef 1.9.2, the DecompressRTF function in lib/ytnef.c allows remote ...)
- TODO: check
+ - libytnef <unfixed>
+ NOTE: https://github.com/Yeraze/ytnef/issues/40
+ NOTE: https://blogs.gentoo.org/ago/2017/05/24/ytnef-heap-based-buffer-overflow-in-decompressrtf-ytnef-c/
CVE-2017-9473 (In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote ...)
TODO: check
CVE-2017-9472 (In ytnef 1.9.2, the SwapDWord function in lib/ytnef.c allows remote ...)
More information about the Secure-testing-commits
mailing list