[Secure-testing-commits] r55416 - data

Raphaël Hertzog hertzog at moszumanska.debian.org
Sun Sep 3 13:29:37 UTC 2017


Author: hertzog
Date: 2017-09-03 13:29:37 +0000 (Sun, 03 Sep 2017)
New Revision: 55416

Modified:
   data/dla-needed.txt
Log:
Add pngcrush to dla-needed.txt

Modified: data/dla-needed.txt
===================================================================
--- data/dla-needed.txt	2017-09-03 13:29:34 UTC (rev 55415)
+++ data/dla-needed.txt	2017-09-03 13:29:37 UTC (rev 55416)
@@ -138,6 +138,10 @@
 phamm
   NOTE: no upstream fixed yet, therefore maintainers not yet contacted
 --
+pncrush
+  NOTE: CVE-2015-7700: the problematic call to png_free_data() is present
+  NOTE: in wheezy but it's not clear to me where the other call to free() is.
+--
 qemu (Guido Günther)
   NOTE: 20170831: at first glance nothing critical, can wait for further issues
 --




More information about the Secure-testing-commits mailing list