From 78dc70d1107dc4aaf3bd5af22a10c082f9215ccd Mon Sep 17 00:00:00 2001 From: Moritz Muehlenhoff Date: Mon, 6 Jul 2020 19:40:24 +0200 Subject: jpeg issue already fixed a few years ago take squid --- data/CVE/list | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'data/CVE') diff --git a/data/CVE/list b/data/CVE/list index 75c8524b38..505badd63d 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -3348,9 +3348,9 @@ CVE-2020-14153 (In IJG JPEG (aka libjpeg) before 9d, jdhuff.c has an out-of-boun NOTE: Not clear what the exact change is between 9c and 9d and whether it applies to -turbo CVE-2020-14152 (In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs. ...) - libjpeg9 1:9d-1 (low) - - libjpeg-turbo (low) + - libjpeg-turbo 1:1.5.2-1 (low) [jessie] - libjpeg-turbo (Minor issue) - TODO: report to libjpeg-turbo upstream + NOTE: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/da2a27ef056a0179cbd80f9146e58b89403d9933 CVE-2020-14151 REJECTED CVE-2020-14150 (GNU Bison before 3.5.4 allows attackers to cause a denial of service ( ...) -- cgit v1.2.3