[Secure-testing-commits] r55548 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Sep 7 16:55:31 UTC 2017


Author: carnil
Date: 2017-09-07 16:55:31 +0000 (Thu, 07 Sep 2017)
New Revision: 55548

Modified:
   data/CVE/list
Log:
Sync status for CVE-2017-7558 with kernel-sec

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-09-07 16:53:02 UTC (rev 55547)
+++ data/CVE/list	2017-09-07 16:55:31 UTC (rev 55548)
@@ -18798,6 +18798,8 @@
 CVE-2017-7558 [sctp: out-of-bounds read in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info()]
 	RESERVED
 	- linux <unfixed>
+	[jessie] - linux <not-affected> (Vulnerable code introduced later 4.7 and not backported)
+	[wheezy] - linux <not-affected> (Vulnerable code introduced later 4.7 and not backported)
 CVE-2017-7557 (dnsdist version 1.1.0 is vulnerable to a flaw in authentication ...)
 	- dnsdist 1.2.0-1 (low; bug #872854)
 	[stretch] - dnsdist <no-dsa> (Minor issue)




More information about the Secure-testing-commits mailing list