[Secure-testing-commits] r53520 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sat Jul 15 20:04:25 UTC 2017


Author: carnil
Date: 2017-07-15 20:04:25 +0000 (Sat, 15 Jul 2017)
New Revision: 53520

Modified:
   data/CVE/list
Log:
Add imagemagick issues as reported by the maintainer

Asked back to Bastien to please request CVEs for those.

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-07-15 19:47:44 UTC (rev 53519)
+++ data/CVE/list	2017-07-15 20:04:25 UTC (rev 53520)
@@ -1,3 +1,38 @@
+CVE-2017-XXXX [avoid a memory leak during screenshot]
+	- imagemagick 8:6.9.7.4+dfsg-12 (bug #867897)
+	NOTE: https://github.com/ImageMagick/ImageMagick/issues/556
+	NOTE: https://github.com/ImageMagick/ImageMagick/commit/8c10b9247509c0484b55330458846115131ec2ae#diff-0a5dc34e461f3c458e758c199f2dc46d
+CVE-2017-XXXX [Avoid heap based overflow for jpeg]
+	- imagemagick 8:6.9.7.4+dfsg-12 (bug #867894)
+	NOTE: https://github.com/ImageMagick/ImageMagick/issues/556
+	NOTE: https://github.com/ImageMagick/ImageMagick/commit/948356eec65aea91995d4b7cc487d197d2c5f602
+CVE-2017-XXXX [memory leak in ReadMATImage in mat.c]
+	- imagemagick 8:6.9.7.4+dfsg-12 (bug #867823)
+	NOTE: https://github.com/ImageMagick/ImageMagick/issues/525
+CVE-2017-XXXX [clear jpeg memory in order to avoid data leak]
+	- imagemagick 8:6.9.7.4+dfsg-12 (bug #867893)
+	NOTE: https://github.com/ImageMagick/ImageMagick/issues/556
+	NOTE: https://github.com/ImageMagick/ImageMagick/commit/1737ac82b335e53376382c07b9a500d73dd2aa11
+CVE-2017-XXXX [CPU exhaustion in ReadOneDJVUImage]
+	- imagemagick 8:6.9.7.4+dfsg-12 (bug #867826)
+	NOTE: https://github.com/ImageMagick/ImageMagick/issues/528
+CVE-2017-XXXX [CPU exhaustion in ReadOneMNGImage]
+	- imagemagick 8:6.9.7.4+dfsg-12 (bug #867825)
+	NOTE: https://github.com/ImageMagick/ImageMagick/issues/527
+CVE-2017-XXXX [CPU exhaustion in ReadOneJNGImage]
+	- imagemagick 8:6.9.7.4+dfsg-12 (bug #867824)
+	NOTE: https://github.com/ImageMagick/ImageMagick/issues/526
+CVE-2017-XXXX [memory exhaustion in ReadEPTImage in ept.c]
+	- imagemagick 8:6.9.7.4+dfsg-12 (bug #867821)
+	NOTE: https://github.com/ImageMagick/ImageMagick/issues/524
+CVE-2017-XXXX [assertion failed in WriteBlob]
+	- imagemagick 8:6.9.7.4+dfsg-12 (bug #867798)
+	NOTE: https://github.com/ImageMagick/ImageMagick/issues/506
+CVE-2017-XXXX [enable heap overflow check for stdin for mpc files]
+	- imagemagick 8:6.9.7.4+dfsg-12 (bug #867896)
+	NOTE: https://github.com/ImageMagick/ImageMagick/issues/556
+	NOTE: https://github.com/ImageMagick/ImageMagick/commit/b007dd3a048097d8f58949297f5b434612e1e1a3#diff-cdb21e3ad4d6e304030bd19bdc881fce
+	NOTE: https://github.com/ImageMagick/ImageMagick/commit/529ff26b68febb2ac03062c58452ea0b4c6edbc1#diff-cdb21e3ad4d6e304030bd19bdc881fce
 CVE-2017-11334
 	RESERVED
 CVE-2017-11333




More information about the Secure-testing-commits mailing list