Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 2c8695e9 by Salvatore Bonaccorso at 2018-03-17T08:03:14+01:00 Add bug reference for CVE-2018-1324/libcommons-compress-java: #893174 - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== --- a/data/CVE/list +++ b/data/CVE/list @@ -19727,7 +19727,7 @@ CVE-2018-1326 CVE-2018-1325 RESERVED CVE-2018-1324 (A specially crafted ZIP archive can be used to cause an infinite loop ...) - - libcommons-compress-java <unfixed> + - libcommons-compress-java <unfixed> (bug #893174) [stretch] - libcommons-compress-java <no-dsa> (Minor issue) [jessie] - libcommons-compress-java <not-affected> (Vulnerable code introduced later) NOTE: Fixed by: https://git-wip-us.apache.org/repos/asf?p=commons-compress.git;a=blobdiff;f=src/main/java/org/apache/commons/compress/archivers/zip/X0017_StrongEncryptionHeader.java;h=acc3b22346b49845e85b5ef27a5814b69e834139;hp=0feb9c98cc622cde1defa3bbd268ef82b4ae5c18;hb=2a2f1dc48e22a34ddb72321a4db211da91aa933b;hpb=dcb0486fb4cb2b6592c04d6ec2edbd3f690df5f2 View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/2c8695e9905a5f50af8bfa771f708432729bb8b4 --- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/2c8695e9905a5f50af8bfa771f708432729bb8b4 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ Secure-testing-commits mailing list Secure-testing-commits@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits