[Secure-testing-commits] r56188 - data

Hugo Lefeuvre hle at moszumanska.debian.org
Wed Sep 27 12:50:30 UTC 2017


Author: hle
Date: 2017-09-27 12:50:30 +0000 (Wed, 27 Sep 2017)
New Revision: 56188

Modified:
   data/dla-needed.txt
Log:
Update mp3gain NOTEs in dla-needed.

Modified: data/dla-needed.txt
===================================================================
--- data/dla-needed.txt	2017-09-27 10:26:02 UTC (rev 56187)
+++ data/dla-needed.txt	2017-09-27 12:50:30 UTC (rev 56188)
@@ -84,7 +84,8 @@
 mosquitto (Roger A. Leigh/Gianfranco Costamagna)
 --
 mp3gain (Hugo Lefeuvre)
-  NOTE: Reproduced CVE-2017-14409, suspect to be a duplicate of something already fixed in mpg123
+  NOTE: successfully reproduced CVE-2017-14409 and CVE-2017-14407.
+  NOTE: bundles a modified, old version of mpg123 under mpglibDBL/, so issues might be already discovered/fixed in mpg123 (or lame?)
 --
 mysql-connector-python
   NOTE: 20170927: Wait for more issues (see ML: https://lists.debian.org/debian-lts/2017/08/msg00039.html) -- Hugo Lefeuvre




More information about the Secure-testing-commits mailing list