[Git][security-tracker-team/security-tracker][master] 2 commits: Add CVE-2018-16335/tiff

Salvatore Bonaccorso carnil at debian.org
Sun Sep 2 09:58:07 BST 2018


Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e9fbe1ad by Salvatore Bonaccorso at 2018-09-02T08:57:22Z
Add CVE-2018-16335/tiff

- - - - -
405a3ae3 by Salvatore Bonaccorso at 2018-09-02T08:57:47Z
Add note for CVE-2018-15209

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,7 +3,10 @@ CVE-2018-16336 (Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows r
 	NOTE: https://github.com/Exiv2/exiv2/issues/400
 	NOTE: https://github.com/Exiv2/exiv2/commit/35b3e596edacd2437c2c5d3dd2b5c9502626163d
 CVE-2018-16335 (newoffsets handling in ChopUpSingleUncompressedStrip in tif_dirread.c ...)
-	TODO: check
+	- tiff <unfixed>
+	- tiff3 <removed>
+	NOTE: http://bugzilla.maptools.org/show_bug.cgi?id=2809
+	NOTE: The fix for CVE-2017-11613 is possibly covering the bug.
 CVE-2018-16334 (An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN and AC10 ...)
 	TODO: check
 CVE-2018-16333 (An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 ...)
@@ -2570,6 +2573,7 @@ CVE-2018-15209 (ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9
 	[jessie] - tiff <not-affected> (Cannot reproduce with crash file)
 	- tiff3 <removed>
 	NOTE: http://bugzilla.maptools.org/show_bug.cgi?id=2808
+	NOTE: The fix for CVE-2017-11613 is possibly covering the bug.
 CVE-2018-15208
 	RESERVED
 CVE-2018-15207



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/fadff97272cca6fe68e1acd5c52b6c5933504f54...405a3ae342b591ad97a09f32ae93e360ecedce4b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/fadff97272cca6fe68e1acd5c52b6c5933504f54...405a3ae342b591ad97a09f32ae93e360ecedce4b
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20180902/7b995932/attachment.html>


More information about the debian-security-tracker-commits mailing list