[Secure-testing-commits] r50224 - in data: . CVE

Guido Guenther agx at moszumanska.debian.org
Fri Mar 31 11:11:01 UTC 2017


Author: agx
Date: 2017-03-31 11:11:01 +0000 (Fri, 31 Mar 2017)
New Revision: 50224

Modified:
   data/CVE/list
   data/dla-needed.txt
Log:
Triage bouncycastle

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-03-31 10:52:18 UTC (rev 50223)
+++ data/CVE/list	2017-03-31 11:11:01 UTC (rev 50224)
@@ -56051,9 +56051,10 @@
 CVE-2015-6645 (SyncManager in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 ...)
 	NOT-FOR-US: Android
 CVE-2015-6644 (Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 ...)
-	- bouncycastle <undetermined>
+	- bouncycastle 1.56-1
 	NOTE: https://source.android.com/security/bulletin/2016-01-01.html#information_disclosure_vulnerability_in_bouncy_castle
 	NOTE: https://android.googlesource.com/platform/external/bouncycastle/+/3e128c5fea3a0ca2d372aa09c4fd4bb0eadfbd3f
+	NOTE: Fixed differently upstream https://github.com/bcgit/bc-java/issues/177#issuecomment-290671336
 CVE-2015-6643 (Setup Wizard in Android 5.x before 5.1.1 LMY49F and 6.0 before ...)
 	NOT-FOR-US: Android
 CVE-2015-6642 (The kernel in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 ...)

Modified: data/dla-needed.txt
===================================================================
--- data/dla-needed.txt	2017-03-31 10:52:18 UTC (rev 50223)
+++ data/dla-needed.txt	2017-03-31 11:11:01 UTC (rev 50224)
@@ -13,6 +13,8 @@
 apng2gif
   NOTE: 24031017: No upstream patch available yet. Have pinged bug#.
 --
+bouncycastle
+--
 ca-certificates
   NOTE: maintainer will handle the upload, see https://lists.debian.org/1acb8e97-8c9f-8b54-348c-0c12f53a8839@pbandjelly.org
 --




More information about the Secure-testing-commits mailing list