[Secure-testing-commits] r56986 - data/CVE
Moritz Muehlenhoff
jmm at moszumanska.debian.org
Thu Oct 26 15:00:25 UTC 2017
Author: jmm
Date: 2017-10-26 15:00:25 +0000 (Thu, 26 Oct 2017)
New Revision: 56986
Modified:
data/CVE/list
Log:
one exiv2 issue n/a
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2017-10-26 14:38:03 UTC (rev 56985)
+++ data/CVE/list 2017-10-26 15:00:25 UTC (rev 56986)
@@ -2642,11 +2642,10 @@
RESERVED
- restlet <itp> (bug #596472)
CVE-2017-14866 (There is a heap-based buffer overflow in the Exiv2::s2Data function of ...)
- - exiv2 <unfixed>
- [wheezy] - exiv2 <not-affected> (Vulnerable code not present)
+ - exiv2 <not-affected> (Versions prior to 0.26 don't parse ICC profiles yet)
NOTE: https://github.com/Exiv2/exiv2/issues/140
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1494781
- TODO: check
+ TODO: file bug against version in experimental
NOTE: Unreproducible on wheezy/jessie/stretch/sid(0.25-3.1).
NOTE: Reproducible in experimental(0.26-1) with valgrind (and "free(): corrupted unsorted chunks" without valgrind).
CVE-2017-14865 (There is a heap-based buffer overflow in the Exiv2::us2Data function of ...)
More information about the Secure-testing-commits
mailing list