[Secure-testing-commits] r52611 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Fri Jun 16 08:01:11 UTC 2017


Author: carnil
Date: 2017-06-16 08:01:11 +0000 (Fri, 16 Jun 2017)
New Revision: 52611

Modified:
   data/CVE/list
Log:
Update status for CVE-2017-9670

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-06-16 07:24:15 UTC (rev 52610)
+++ data/CVE/list	2017-06-16 08:01:11 UTC (rev 52611)
@@ -111,7 +111,8 @@
 CVE-2017-9670 (An uninitialized stack variable vulnerability in load_tic_series() in ...)
 	- gnuplot <undetermined>
 	NOTE: https://sourceforge.net/p/gnuplot/bugs/1933/
-	TODO: check
+	NOTE: The specific CVE is for the uninitialized stack variable fixed via set.c
+	NOTE: Patch: https://sourceforge.net/p/gnuplot/bugs/_discuss/thread/44ec637c/af0f/attachment/uninitialized_variables_%28Bug1933%29.patch
 CVE-2017-9669
 	RESERVED
 CVE-2017-9668




More information about the Secure-testing-commits mailing list