[Secure-testing-commits] r52785 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Wed Jun 21 17:10:58 UTC 2017


Author: carnil
Date: 2017-06-21 17:10:57 +0000 (Wed, 21 Jun 2017)
New Revision: 52785

Modified:
   data/CVE/list
Log:
Add unrar-nonfree issue, no-dsa

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-06-21 16:54:48 UTC (rev 52784)
+++ data/CVE/list	2017-06-21 17:10:57 UTC (rev 52785)
@@ -1,3 +1,9 @@
+CVE-2017-XXXX [VMSF_DELTA filter in unrar allows arbitrary memory write]
+	- unrar-nonfree <unfixed> (bug #865461)
+	[stretch] - unrar-nonfree <no-dsa> (Non-free not supported)
+	[jessie] - unrar-nonfree <no-dsa> (Non-free not supported)
+	NOTE: http://www.openwall.com/lists/oss-security/2017/06/21/9
+	NOTE: https://bugs.chromium.org/p/project-zero/issues/detail?id=1286&desc=6
 CVE-2017-9778 (GNU Debugger (GDB) 8.0 and earlier fails to detect a negative length ...)
 	- gdb <unfixed>
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=21600




More information about the Secure-testing-commits mailing list