Add note for CVE-2017-14617/poppler
The (pending) uploads of poppler/0.48.0-2+deb9u1 (stetch-security) and poppler/0.26.5-2+deb8u2 do contain the https://cgit.freedesktop.org/poppler/poppler/commit/?id=939465c40902d72e0c05d4f3a27ee67e4a007ed7 applied, but applying this patch alone is not enough to fix the issue. The upload was not rejected, instead we mark the issue still as unfixed for CVE-2017-14617. The issue is OTOH as well faily minor that it does not deserve a DSA on it's own, a complete fix might be included in a later DSA or via a point release.
Loading
Please register or sign in to comment