[Git][security-tracker-team/security-tracker][master] 2 commits: Update status for CVE-2018-16335/tiff
Salvatore Bonaccorso
carnil at debian.org
Sun Oct 21 20:10:31 BST 2018
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3746e564 by Salvatore Bonaccorso at 2018-10-21T19:08:25Z
Update status for CVE-2018-16335/tiff
Altough the issue is adressed with same set of commits as CVE-2017-11613
it still was considered different issue. Fixup status according to
unstable introducing fix.
- - - - -
e51e3f8b by Salvatore Bonaccorso at 2018-10-21T19:09:52Z
Update status for CVE-2018-15209/tiff
Altough the issue is adressed with same set of commits as CVE-2017-11613
it still was considered different issue. Fixup status according to
unstable introducing fix.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -5414,12 +5414,14 @@ CVE-2018-16336 (Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows r
NOTE: https://github.com/Exiv2/exiv2/issues/400
NOTE: https://github.com/Exiv2/exiv2/commit/35b3e596edacd2437c2c5d3dd2b5c9502626163d
CVE-2018-16335 (newoffsets handling in ChopUpSingleUncompressedStrip in tif_dirread.c ...)
- - tiff <unfixed> (bug #907795)
+ - tiff 4.0.9-5 (bug #907795)
[stretch] - tiff <postponed> (Can be fixed along in future DSA)
[jessie] - tiff <postponed> (Can be fixed along in future DLA)
- tiff3 <removed>
NOTE: http://bugzilla.maptools.org/show_bug.cgi?id=2809
- NOTE: The fix for CVE-2017-11613 is possibly covering the bug.
+ NOTE: Different issue than CVE-2017-11613 but adressed with same set of commits.
+ NOTE: Upstream fix 1/2: https://gitlab.com/libtiff/libtiff/commit/3719385a3fac5cfb20b487619a5f08abbf967cf8
+ NOTE: Upstream fix 2/2: https://gitlab.com/libtiff/libtiff/commit/7a092f8af2568d61993a8cc2e7a35a998d7d37be
CVE-2018-16334 (An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN and AC10 ...)
NOT-FOR-US: Tenda
CVE-2018-16333 (An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 ...)
@@ -8148,12 +8150,14 @@ CVE-2018-15211
CVE-2018-15210
RESERVED
CVE-2018-15209 (ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows ...)
- - tiff <unfixed> (bug #905798)
+ - tiff 4.0.9-5 (bug #905798)
[stretch] - tiff <postponed> (Can be fixed along in future DSA)
[jessie] - tiff <not-affected> (Cannot reproduce with crash file)
- tiff3 <removed>
NOTE: http://bugzilla.maptools.org/show_bug.cgi?id=2808
- NOTE: The fix for CVE-2017-11613 is possibly covering the bug.
+ NOTE: Different issue than CVE-2017-11613 but adressed with same set of commits.
+ NOTE: Upstream fix 1/2: https://gitlab.com/libtiff/libtiff/commit/3719385a3fac5cfb20b487619a5f08abbf967cf8
+ NOTE: Upstream fix 2/2: https://gitlab.com/libtiff/libtiff/commit/7a092f8af2568d61993a8cc2e7a35a998d7d37be
CVE-2018-15208
RESERVED
CVE-2018-15207
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/6722e85895d7d3e07c99b684c91c774f564d3a75...e51e3f8b03733c80acc32cd9bea06dd4727b8d47
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/6722e85895d7d3e07c99b684c91c774f564d3a75...e51e3f8b03733c80acc32cd9bea06dd4727b8d47
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20181021/f7cc62fc/attachment.html>
More information about the debian-security-tracker-commits
mailing list