[Secure-testing-commits] r52485 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sun Jun 11 15:21:44 UTC 2017


Author: carnil
Date: 2017-06-11 15:21:44 +0000 (Sun, 11 Jun 2017)
New Revision: 52485

Modified:
   data/CVE/list
Log:
Update status for CVE-2014-0158

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-06-11 15:14:22 UTC (rev 52484)
+++ data/CVE/list	2017-06-11 15:21:44 UTC (rev 52485)
@@ -108389,8 +108389,6 @@
 CVE-2014-0159 (Buffer overflow in the GetStatistics64 remote procedure call (RPC) in ...)
 	{DSA-2899-1}
 	- openafs 1.6.7-1
-CVE-2014-0158
-	RESERVED
 CVE-2014-0157 (Cross-site scripting (XSS) vulnerability in the Horizon Orchestration ...)
 	- horizon 2013.2.3-1 (bug #744019)
 	[wheezy] - horizon <not-affected> (Vulnerable code not present)
@@ -124124,6 +124122,14 @@
 	RESERVED
 CVE-2013-1448
 	RESERVED
+CVE-2014-0158
+	- openjpeg 1.3+dfsg-4.7
+	NOTE: Not considering a duplicate of CVE-2013-1447 following
+	NOTE: http://www.openwall.com/lists/oss-security/2014/04/02/2 . A query
+	NOTE: to MITRE though indicated that CVE-2014-0158 will not be REJECTED
+	NOTE: since people might have tracked CVE-2014-0158 of the much higher
+	NOTE: impact as due https://bugzilla.redhat.com/show_bug.cgi?id=1082925
+	NOTE: and https://bugzilla.suse.com/show_bug.cgi?id=871412
 CVE-2013-1447 (OpenJPEG 1.3 and earlier allows remote attackers to cause a denial of ...)
 	{DSA-2808-1}
 	- openjpeg 1.3+dfsg-4.7 (bug #731237)




More information about the Secure-testing-commits mailing list