[Secure-testing-commits] r56632 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Oct 12 06:39:02 UTC 2017


Author: carnil
Date: 2017-10-12 06:39:02 +0000 (Thu, 12 Oct 2017)
New Revision: 56632

Modified:
   data/CVE/list
Log:
Add CVE-2017-15268/qemu

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-10-12 06:10:15 UTC (rev 56631)
+++ data/CVE/list	2017-10-12 06:39:02 UTC (rev 56632)
@@ -1,5 +1,9 @@
-CVE-2017-15268
+CVE-2017-15268 [I/O: potential memory exhaustion via websock connection to VNC]
 	RESERVED
+	- qemu <unfixed>
+	- qemu-kvm <removed>
+	NOTE: https://lists.gnu.org/archive/html/qemu-devel/2017-10/msg02278.html
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1496879
 CVE-2017-15267 (In GNU Libextractor 1.4, there is a NULL Pointer Dereference in ...)
 	- libextractor <unfixed>
 	NOTE: http://lists.gnu.org/archive/html/bug-libextractor/2017-10/msg00003.html




More information about the Secure-testing-commits mailing list