[Secure-testing-commits] r56494 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sat Oct 7 13:03:30 UTC 2017


Author: carnil
Date: 2017-10-07 13:03:29 +0000 (Sat, 07 Oct 2017)
New Revision: 56494

Modified:
   data/CVE/list
Log:
CVE-2017-13735 fixed in unstable upload

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-10-07 13:03:14 UTC (rev 56493)
+++ data/CVE/list	2017-10-07 13:03:29 UTC (rev 56494)
@@ -3725,8 +3725,10 @@
 	- graphicsmagick <unfixed> (unimportant)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1484192
 CVE-2017-13735 (There is a floating point exception in the kodak_radc_load_raw function ...)
-	- libraw <unfixed> (low; bug #874729)
+	- libraw 0.18.5-1 (low; bug #874729)
 	[wheezy] - libraw <no-dsa> (Minor issue)
+	NOTE: https://github.com/LibRaw/LibRaw/issues/96
+	NOTE: Isolated patch: https://github.com/LibRaw/LibRaw/files/1276421/radc_divbyzero.txt
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1483988
 CVE-2017-13734 (There is an illegal address access in the _nc_safe_strcat function in ...)
 	- ncurses 6.0+20170827-1 (bug #873723)




More information about the Secure-testing-commits mailing list