[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Move CVE-2017-17485 back to unfixed

Salvatore Bonaccorso carnil at debian.org
Wed Jan 24 22:08:06 UTC 2018


Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
335db9f3 by Salvatore Bonaccorso at 2018-01-24T23:07:41+01:00
Move CVE-2017-17485 back to unfixed

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -12152,8 +12152,10 @@ CVE-2017-17487
 CVE-2017-17486
 	RESERVED
 CVE-2017-17485 (FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 ...)
-	- jackson-databind <not-affected> (Specific incomplete fixes for some Red Hat packages)
+	- jackson-databind <unfixed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1528565#c0
+	NOTE: https://github.com/FasterXML/jackson-databind/issues/1855
+	TODO: check
 CVE-2017-17484 (The ucnv_UTF8FromUTF8 function in ucnv_u8.cpp in International ...)
 	[experimental] - icu 60.2-1
 	- icu <unfixed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/335db9f368019cd522b4e6c72937d2dbda49f8d9

---
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/335db9f368019cd522b4e6c72937d2dbda49f8d9
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.alioth.debian.org/pipermail/secure-testing-commits/attachments/20180124/ef4f7bba/attachment.html>


More information about the Secure-testing-commits mailing list