[Secure-testing-commits] r52384 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Wed Jun 7 12:07:27 UTC 2017


Author: carnil
Date: 2017-06-07 12:07:27 +0000 (Wed, 07 Jun 2017)
New Revision: 52384

Modified:
   data/CVE/list
Log:
Record information for CVE-2017-9473/libytnef

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-06-07 12:05:54 UTC (rev 52383)
+++ data/CVE/list	2017-06-07 12:07:27 UTC (rev 52384)
@@ -51,7 +51,9 @@
 	NOTE: https://github.com/Yeraze/ytnef/issues/40
 	NOTE: https://blogs.gentoo.org/ago/2017/05/24/ytnef-heap-based-buffer-overflow-in-decompressrtf-ytnef-c/
 CVE-2017-9473 (In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote ...)
-	TODO: check
+	- libytnef <unfixed>
+	NOTE: https://github.com/Yeraze/ytnef/issues/42
+	NOTE: https://blogs.gentoo.org/ago/2017/05/24/ytnef-memory-allocation-failure-in-tneffillmapi-ytnef-c/
 CVE-2017-9472 (In ytnef 1.9.2, the SwapDWord function in lib/ytnef.c allows remote ...)
 	TODO: check
 CVE-2017-9471 (In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote ...)




More information about the Secure-testing-commits mailing list