[Secure-testing-commits] r47254 - data/CVE

Antoine Beaupré anarcat at moszumanska.debian.org
Tue Dec 20 19:57:47 UTC 2016


Author: anarcat
Date: 2016-12-20 19:57:47 +0000 (Tue, 20 Dec 2016)
New Revision: 47254

Modified:
   data/CVE/list
Log:
#845196 wasn't fixed completely by jessie upload

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-12-20 19:56:53 UTC (rev 47253)
+++ data/CVE/list	2016-12-20 19:57:47 UTC (rev 47254)
@@ -8924,8 +8924,10 @@
 	NOTE: https://github.com/ImageMagick/ImageMagick/commit/2bb6941a2d557f26a2f2049ade466e118eeaab91
 CVE-2016-XXXX [Check return of write function]
 	- imagemagick 8:6.9.6.2+dfsg-2 (bug #845196)
-	[jessie] - imagemagick 8:6.8.9.9-5+deb8u6
 	NOTE: Workaround entry for DSA-3726-1 until CVEs assigned
+	NOTE: https://github.com/ImageMagick/ImageMagick/commit/4e914bbe371433f0590cefdf3bd5f3a5710069f9
+	NOTE: https://github.com/ImageMagick/ImageMagick/commit/933e96f01a8c889c7bf5ffd30020e86a02a046e7
+	NOTE: latter patch was missing from 8:6.8.9.9-5+deb8u6 upload so DSA-3726-1 was incomplete
 CVE-2016-XXXX [Imagemagick (jessie and older) buffer overflow]
 	- imagemagick 8:6.9.6.2+dfsg-2 (bug #845195)
 	[jessie] - imagemagick 8:6.8.9.9-5+deb8u6




More information about the Secure-testing-commits mailing list