[Secure-testing-commits] r57055 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sat Oct 28 09:01:55 UTC 2017


Author: carnil
Date: 2017-10-28 09:01:55 +0000 (Sat, 28 Oct 2017)
New Revision: 57055

Modified:
   data/CVE/list
Log:
Update information for CVE-2016-15864/redis

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-10-28 08:54:21 UTC (rev 57054)
+++ data/CVE/list	2017-10-28 09:01:55 UTC (rev 57055)
@@ -170,8 +170,8 @@
 CVE-2017-15864
 	RESERVED
 CVE-2016-10517 (networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" ...)
-	- redis <unfixed>
-	TODO: check
+	- redis 3:3.2.7-1
+	NOTE: https://github.com/antirez/redis/commit/874804da0c014a7d704b3d285aa500098a931f50
 CVE-2017-15863 (Cross Site Scripting (XSS) exists in the wp-noexternallinks plugin ...)
 	NOT-FOR-US: WordPress plugin wp-noexternallinks
 CVE-2017-15862




More information about the Secure-testing-commits mailing list