[Secure-testing-commits] r52495 - in data: . CVE

Ola Lundqvist opal at moszumanska.debian.org
Sun Jun 11 20:15:54 UTC 2017


Author: opal
Date: 2017-06-11 20:15:54 +0000 (Sun, 11 Jun 2017)
New Revision: 52495

Modified:
   data/CVE/list
   data/dla-needed.txt
Log:
Some issues will not be fixed by upstream but others are worth fixing.

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-06-11 20:08:28 UTC (rev 52494)
+++ data/CVE/list	2017-06-11 20:15:54 UTC (rev 52495)
@@ -1328,14 +1328,17 @@
 	NOTE: https://github.com/openexr/openexr/issues/232
 CVE-2017-9115 (In OpenEXR 2.2.0, an invalid write of size 2 in the = operator function ...)
 	- openexr <unfixed> (bug #864078)
+	[wheezy] - openexr <no-dsa> (Minor issue)
 	NOTE: http://www.openwall.com/lists/oss-security/2017/05/12/5
 	NOTE: https://github.com/openexr/openexr/issues/232
 CVE-2017-9114 (In OpenEXR 2.2.0, an invalid read of size 1 in the refill function in ...)
 	- openexr <unfixed> (bug #864078)
+	[wheezy] - openexr <no-dsa> (Minor issue)
 	NOTE: http://www.openwall.com/lists/oss-security/2017/05/12/5
 	NOTE: https://github.com/openexr/openexr/issues/232
 CVE-2017-9113 (In OpenEXR 2.2.0, an invalid write of size 1 in the bufferedReadPixels ...)
 	- openexr <unfixed> (bug #864078)
+	[wheezy] - openexr <no-dsa> (Minor issue)
 	NOTE: http://www.openwall.com/lists/oss-security/2017/05/12/5
 	NOTE: https://github.com/openexr/openexr/issues/232
 CVE-2017-9112 (In OpenEXR 2.2.0, an invalid read of size 1 in the getBits function in ...)
@@ -1344,6 +1347,7 @@
 	NOTE: https://github.com/openexr/openexr/issues/232
 CVE-2017-9111 (In OpenEXR 2.2.0, an invalid write of size 8 in the storeSSE function ...)
 	- openexr <unfixed> (bug #864078)
+	[wheezy] - openexr <no-dsa> (Minor issue)
 	NOTE: http://www.openwall.com/lists/oss-security/2017/05/12/5
 	NOTE: https://github.com/openexr/openexr/issues/232
 CVE-2017-9110 (In OpenEXR 2.2.0, an invalid read of size 2 in the hufDecode function ...)

Modified: data/dla-needed.txt
===================================================================
--- data/dla-needed.txt	2017-06-11 20:08:28 UTC (rev 52494)
+++ data/dla-needed.txt	2017-06-11 20:15:54 UTC (rev 52495)
@@ -83,6 +83,8 @@
 mysql-workbench
   NOTE: maintainer contacted 20170429
 --
+openexr
+--
 otrs2
 --
 postgresql-9.1 (Christoph Berg)




More information about the Secure-testing-commits mailing list