[Git][security-tracker-team/security-tracker][master] Update information for (ancient) CVE-2016-3177 (issue fixed)

Salvatore Bonaccorso carnil at debian.org
Sun Aug 18 09:40:31 BST 2019



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
388cce01 by Salvatore Bonaccorso at 2019-08-18T08:39:50Z
Update information for (ancient) CVE-2016-3177 (issue fixed)

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -168186,9 +168186,11 @@ CVE-2016-3180 (Tor Browser Launcher (aka torbrowser-launcher) before 0.2.4, duri
 	[jessie] - torbrowser-launcher 0.1.9-1+deb8u3
 	NOTE: https://github.com/micahflee/torbrowser-launcher/issues/229
 CVE-2016-3177 (Multiple use-after-free and double-free vulnerabilities in gifcolor.c  ...)
-	- giflib <unfixed> (unimportant)
+	- giflib 5.1.4-0.1 (unimportant)
+	[jessie] - giflib <not-affected> (Vulnerable code introduced in 5.1.2)
 	NOTE: https://sourceforge.net/p/giflib/bugs/83/
 	NOTE: Issue only in gifcolor utility, not installed into giflib-tools
+	NOTE: Issue introduced upstream in 5.1.2 and fixed in 5.1.3.
 CVE-2016-3176 (Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external  ...)
 	- salt 2015.8.8+ds-1 (bug #819184)
 	[jessie] - salt <no-dsa> (Minor issue; external_auth not by default usable)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/388cce01cdc660b51db23ced60be72264fec1ee1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/388cce01cdc660b51db23ced60be72264fec1ee1
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190818/e20978ce/attachment.html>


More information about the debian-security-tracker-commits mailing list