Author: carnil
Date: 2017-05-09 05:36:29 +0000 (Tue, 09 May 2017)
New Revision: 51429

Modified:
   data/CVE/list
Log:
Add three more lrzip issues

Modified: data/CVE/list
===================================================================
--- data/CVE/list       2017-05-09 05:35:17 UTC (rev 51428)
+++ data/CVE/list       2017-05-09 05:36:29 UTC (rev 51429)
@@ -20,11 +20,17 @@
        NOTE: 
https://blogs.gentoo.org/ago/2017/05/07/lrzip-invalid-memory-read-in-lzo_decompress_buf-stream-c/
        TODO: check if issue to be addressed via lrzip
 CVE-2017-8844 (The read_1g function in stream.c in liblrzip.so in lrzip 0.631 
allows ...)
-       TODO: check
+       - lrzip <unfixed>
+       NOTE: https://github.com/ckolivas/lrzip/issues/70
+       NOTE: 
https://blogs.gentoo.org/ago/2017/05/07/lrzip-heap-based-buffer-overflow-write-in-read_1g-stream-c/
 CVE-2017-8843 (The join_pthread function in stream.c in liblrzip.so in lrzip 
0.631 ...)
-       TODO: check
+       - lrzip <unfixed>
+       NOTE: https://github.com/ckolivas/lrzip/issues/69
+       NOTE: 
https://blogs.gentoo.org/ago/2017/05/07/lrzip-null-pointer-dereference-in-join_pthread-stream-c/
 CVE-2017-8842 (The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so 
in ...)
-       TODO: check
+       - lrzip <unfixed>
+       NOTE: https://github.com/ckolivas/lrzip/issues/66
+       NOTE: 
https://blogs.gentoo.org/ago/2017/05/07/lrzip-divide-by-zero-in-bufreadget-libzpaq-h/
 CVE-2017-8841
        RESERVED
 CVE-2017-8840


_______________________________________________
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits

Reply via email to