Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
23ad3c3c by Salvatore Bonaccorso at 2018-01-02T16:21:49+01:00
Add note for CVE-2017-14617/poppler

The (pending) uploads of poppler/0.48.0-2+deb9u1 (stetch-security) and
poppler/0.26.5-2+deb8u2 do contain the

https://cgit.freedesktop.org/poppler/poppler/commit/?id=939465c40902d72e0c05d4f3a27ee67e4a007ed7

applied, but applying this patch alone is not enough to fix the issue.
The upload was not rejected, instead we mark the issue still as unfixed
for CVE-2017-14617. The issue is OTOH as well faily minor that it does
not deserve a DSA on it's own, a complete fix might be included in a
later DSA or via a point release.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -17704,6 +17704,9 @@ CVE-2017-14617 (In Poppler 0.59.0, a floating point 
exception occurs in the Imag
        [jessie] - poppler <no-dsa> (Minor issue)
        NOTE: https://bugs.freedesktop.org/show_bug.cgi?id=102854
        NOTE: 
https://cgit.freedesktop.org/poppler/poppler/commit/?id=939465c40902d72e0c05d4f3a27ee67e4a007ed7
+       NOTE: The patch applied in 0.48.0-2+deb9u1 (stretch) and 
0.26.5-2+deb8u2 (jessie)
+       NOTE:  does not completely fix the issue thus still marked as unfixed 
even if the
+       NOTE: CVE is recorded in debian/changelog.
 CVE-2015-9232 (The Good for Enterprise application 3.0.0.415 for Android does 
not use ...)
        NOT-FOR-US: Good for Enterprise application for Android
 CVE-2017-14616 (An FBX-5312 issue was discovered in WatchGuard Fireware before 
12.0. If ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/commit/23ad3c3ce293596e8274270d4ac09c8098e957a8

---
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/commit/23ad3c3ce293596e8274270d4ac09c8098e957a8
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
Secure-testing-commits mailing list
Secure-testing-commits@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits

Reply via email to