[Secure-testing-commits] r49785 - data

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sun Mar 19 07:35:41 UTC 2017


Author: carnil
Date: 2017-03-19 07:35:41 +0000 (Sun, 19 Mar 2017)
New Revision: 49785

Modified:
   data/dla-needed.txt
Log:
Add a note for libplist

Modified: data/dla-needed.txt
===================================================================
--- data/dla-needed.txt	2017-03-19 07:30:14 UTC (rev 49784)
+++ data/dla-needed.txt	2017-03-19 07:35:41 UTC (rev 49785)
@@ -58,6 +58,8 @@
 libplist (Markus Koschany)
   NOTE: Fixed CVE-2017-6435, CVE-2017-6436. CVE-2017-6439 is probably a duplicate of CVE-2017-6436.
   NOTE: The rest is still unfixed/more information needed.
+  NOTE: Although CVE-2017-6439 and CVE-2017-6436 have same fixing commit the codepath
+  NOTE: to trigger the issue is different, and thus are treated as two different issues.
 --
 libpodofo
   NOTE: 20170310: No patches available.




More information about the Secure-testing-commits mailing list