Author: carnil Date: 2017-11-28 15:13:54 +0000 (Tue, 28 Nov 2017) New Revision: 58078
Modified: data/CVE/list Log: Add fixing version for busybox Modified: data/CVE/list =================================================================== --- data/CVE/list 2017-11-28 14:02:09 UTC (rev 58077) +++ data/CVE/list 2017-11-28 15:13:54 UTC (rev 58078) @@ -2870,7 +2870,7 @@ NOTE: the severity of the wheezy version is low even though the vulnerable code is still present. NOTE: The patch is trivial so it may be worth fixing in combination with some other fix. CVE-2017-16544 (In the add_match function in libbb/lineedit.c in BusyBox through ...) - - busybox <unfixed> (bug #882258) + - busybox 1:1.27.2-2 (bug #882258) [stretch] - busybox <no-dsa> (Minor issue, can be fixed via point release) [jessie] - busybox <no-dsa> (Minor issue, can be fixed via point release) [wheezy] - busybox <no-dsa> (Minor issue) @@ -4830,7 +4830,7 @@ CVE-2017-15875 RESERVED CVE-2017-15874 (archival/libarchive/decompress_unlzma.c in BusyBox 1.27.2 has an ...) - - busybox <unfixed> (bug #879732) + - busybox 1:1.27.2-2 (bug #879732) [stretch] - busybox <not-affected> (Vulnerable code not present) [jessie] - busybox <not-affected> (Vulnerable code not present) [wheezy] - busybox <not-affected> (Vulnerable code not present) @@ -4838,7 +4838,7 @@ NOTE: Introduced in: https://git.busybox.net/busybox/commit/?id=3989e5adf454a3ab98412b249c2c9bd2a3175ae0 NOTE: Fixed by: https://git.busybox.net/busybox/commit/?id=9ac42c500586fa5f10a1f6d22c3f797df11b1f6b CVE-2017-15873 (The get_next_block function in archival/libarchive/decompress_bunzip2.c ...) - - busybox <unfixed> (bug #879732) + - busybox 1:1.27.2-2 (bug #879732) [stretch] - busybox <no-dsa> (Minor issue) [jessie] - busybox <no-dsa> (Minor issue) [wheezy] - busybox <no-dsa> (Minor issue) _______________________________________________ Secure-testing-commits mailing list Secure-testing-commits@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits