[Secure-testing-commits] r55791 - data/CVE

Moritz Muehlenhoff jmm at moszumanska.debian.org
Fri Sep 15 15:09:26 UTC 2017


Author: jmm
Date: 2017-09-15 15:09:26 +0000 (Fri, 15 Sep 2017)
New Revision: 55791

Modified:
   data/CVE/list
Log:
binutils fixed
two unrar issues unimportant


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-09-15 14:55:25 UTC (rev 55790)
+++ data/CVE/list	2017-09-15 15:09:26 UTC (rev 55791)
@@ -952,7 +952,7 @@
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=22058
 	NOTE: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=2a143b99fc4a5094a9cf128f3184d8e6818c8229
 CVE-2017-14129 (The read_section function in dwarf2.c in the Binary File Descriptor ...)
-	- binutils <unfixed> (low)
+	- binutils 2.29-10 (low)
 	[stretch] - binutils <ignored> (Minor issue)
 	[jessie] - binutils <ignored> (Minor issue)
 	[wheezy] - binutils <ignored> (Minor issue)
@@ -976,13 +976,13 @@
 CVE-2017-14123 (Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File ...)
 	NOT-FOR-US: Zoho ManageEngine
 CVE-2017-14122 (unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a stack-based ...)
-	- unrar-free <unfixed> (bug #874060)
-	[wheezy] - unrar-free <no-dsa> (Minor issue)
+	- unrar-free <unfixed> (unimportant; bug #874060)
 	NOTE: http://www.openwall.com/lists/oss-security/2017/08/20/1
+	NOTE: Crash in CLI tool, no security impact
 CVE-2017-14121 (The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free ...)
-	- unrar-free <unfixed> (bug #874061)
-	[wheezy] - unrar-free <no-dsa> (Minor issue)
+	- unrar-free <unfixed> (unimportant; bug #874061)
 	NOTE: http://www.openwall.com/lists/oss-security/2017/08/20/1
+	NOTE: Crash in CLI tool, no security impact
 CVE-2017-14120 (unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a directory ...)
 	{DLA-1091-1}
 	- unrar-free 1:0.0.1+cvs20140707-2 (bug #874059)




More information about the Secure-testing-commits mailing list