[Secure-testing-commits] r51450 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Tue May 9 17:31:21 UTC 2017


Author: carnil
Date: 2017-05-09 17:31:21 +0000 (Tue, 09 May 2017)
New Revision: 51450

Modified:
   data/CVE/list
Log:
Mark CVE-2017-8419 as fixed in 3.99.5+repack1-7

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-05-09 15:13:20 UTC (rev 51449)
+++ data/CVE/list	2017-05-09 17:31:21 UTC (rev 51450)
@@ -953,8 +953,10 @@
 CVE-2017-8420
 	RESERVED
 CVE-2017-8419 (LAME through 3.99.5 relies on the signed integer data type for values ...)
-	- lame <unfixed>
+	- lame 3.99.5+repack1-7
 	NOTE: https://sourceforge.net/p/lame/bugs/458/
+	NOTE: Issue addressed in Debian via: https://sources.debian.net/patches/lame/3.99.5%2Brepack1-9/0001-Add-check-for-invalid-input-sample-rate.patch/
+	NOTE: in the revised version as included in 3.99.5+repack1-7
 CVE-2016-10366
 	RESERVED
 CVE-2016-10365




More information about the Secure-testing-commits mailing list