[Secure-testing-commits] r42162 - data/CVE

Markus Koschany apo at moszumanska.debian.org
Mon May 30 17:56:23 UTC 2016


Author: apo
Date: 2016-05-30 17:56:23 +0000 (Mon, 30 May 2016)
New Revision: 42162

Modified:
   data/CVE/list
Log:
Add link to fix for CVE-2016-5118


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-05-30 17:55:33 UTC (rev 42161)
+++ data/CVE/list	2016-05-30 17:56:23 UTC (rev 42162)
@@ -18,6 +18,7 @@
 CVE-2016-5118 [popen() shell vulnerability via filename]
 	- imagemagick <unfixed> (bug #825799)
 	- graphicsmagick <unfixed> (bug #825800)
+	NOTE: fixed by http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/ae3928faa858
 CVE-2016-5116 [xbm: avoid stack overflow (read) with large names]
 	- libgd2 2.2.1-1
 	[wheezy] - libgd2 <not-affected> (Vulnerable code not present)




More information about the Secure-testing-commits mailing list