[Secure-testing-commits] r57447 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Wed Nov 8 09:55:54 UTC 2017


Author: carnil
Date: 2017-11-08 09:55:54 +0000 (Wed, 08 Nov 2017)
New Revision: 57447

Modified:
   data/CVE/list
Log:
Add one new php issue

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-11-08 09:42:21 UTC (rev 57446)
+++ data/CVE/list	2017-11-08 09:55:54 UTC (rev 57447)
@@ -37,7 +37,13 @@
 CVE-2017-16643 (The parse_hid_report_descriptor function in drivers/input/tablet/gtco.c ...)
 	- linux <unfixed>
 CVE-2017-16642 (In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an ...)
-	TODO: check
+	- php7.1 <unfixed>
+	- php7.0 <unfixed>
+	- php5 <removed>
+	NOTE: Fixed in: 5.6.32, 7.0.25, 7.1.11
+	NOTE: PHP Bug: https://bugs.php.net/bug.php?id=75055
+	NOTE: https://github.com/derickr/timelib/commit/aa9156006e88565e1f1a5f7cc088b18322d57536
+	NOTE: https://github.com/php/php-src/commit/5c0455bf2c8cd3c25401407f158e820aa3b239e1
 CVE-2017-16661 (Cacti 1.1.27 allows remote authenticated administrators to read ...)
 	- cacti <unfixed>
 	NOTE: https://github.com/Cacti/cacti/issues/1066




More information about the Secure-testing-commits mailing list