Public bug reported:

The current package available to 14.04/trusty is 1:1.2.8.dfsg-1ubuntu1
which does not have the upstream fixes for the following CVEs:

* CVE-2016-9840 (high) (https://nvd.nist.gov/vuln/detail/CVE-2016-9840)
* CVE-2016-9841 (critical) (https://nvd.nist.gov/vuln/detail/CVE-2016-9841)
* CVE-2016-9842 (high) (https://nvd.nist.gov/vuln/detail/CVE-2016-9842)
* CVE-2016-9843 (critical) (https://nvd.nist.gov/vuln/detail/CVE-2016-9843)

Being that they are being categorized as such by NIST, it would be very
nice to get these fixes backported to Trusty or the most recent version
of zlib made available to Trusty.

Thanks!

** Affects: zlib (Ubuntu)
     Importance: Undecided
         Status: New


** Tags: trusty

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1729414

Title:
  zlib package in Ubuntu 14.04 LTS (Trusty) has not received patches for
  critical/high CVE-2016-9840, CVE-2016-9841, CVE-2016-9842,
  CVE-2016-9843

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/zlib/+bug/1729414/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to