[Secure-testing-commits] r55777 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Fri Sep 15 06:41:17 UTC 2017


Author: carnil
Date: 2017-09-15 06:41:17 +0000 (Fri, 15 Sep 2017)
New Revision: 55777

Modified:
   data/CVE/list
Log:
Add CVE-2017-14033/ruby

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-09-15 06:38:31 UTC (rev 55776)
+++ data/CVE/list	2017-09-15 06:41:17 UTC (rev 55777)
@@ -1233,8 +1233,13 @@
 	NOTE: https://patchwork.kernel.org/patch/9929625/
 CVE-2017-14034
 	RESERVED
-CVE-2017-14033
+CVE-2017-14033 [Buffer underrun in OpenSSL ASN1 decode]
 	RESERVED
+	- ruby2.3 <unfixed>
+	- ruby2.1 <removed>
+	- ruby1.9.1 <removed>
+	NOTE: https://bugzilla.novell.com/show_bug.cgi?id=1058757
+	NOTE: https://www.ruby-lang.org/en/news/2017/09/14/openssl-asn1-buffer-underrun-cve-2017-14033/
 CVE-2017-14031
 	RESERVED
 CVE-2017-14030




More information about the Secure-testing-commits mailing list