[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Add CVE-2017-17858/mupdf

Salvatore Bonaccorso carnil at debian.org
Wed Jan 24 07:47:01 UTC 2018


Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
50493a22 by Salvatore Bonaccorso at 2018-01-24T08:46:28+01:00
Add CVE-2017-17858/mupdf

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -6342,7 +6342,9 @@ CVE-2017-17860 (In Samsung Gear products, Bluetooth link key is updated to the .
 CVE-2017-17859 (Samsung Internet Browser 6.2.01.12 allows remote attackers to bypass ...)
 	NOT-FOR-US: Samsung Internet Browser
 CVE-2017-17858 (Heap-based buffer overflow in the ensure_solid_xref function in ...)
-	TODO: check
+	- mupdf <unfixed>
+	NOTE: https://bugs.ghostscript.com/show_bug.cgi?id=698819 (not public)
+	NOTE: http://git.ghostscript.com/?p=mupdf.git;a=commit;h=55c3f68d638ac1263a386e0aaa004bb6e8bde731
 CVE-2017-17851
 	RESERVED
 CVE-2017-17850 (An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/50493a221209d952bb3a387f3c5c64976efef6aa

---
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/50493a221209d952bb3a387f3c5c64976efef6aa
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.alioth.debian.org/pipermail/secure-testing-commits/attachments/20180124/46b5a91d/attachment.html>


More information about the Secure-testing-commits mailing list