[Secure-testing-commits] r53522 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sat Jul 15 20:24:49 UTC 2017


Author: carnil
Date: 2017-07-15 20:24:49 +0000 (Sat, 15 Jul 2017)
New Revision: 53522

Modified:
   data/CVE/list
Log:
Record fixes for CVE-2017-11166 for stretch and jessie

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-07-15 20:21:13 UTC (rev 53521)
+++ data/CVE/list	2017-07-15 20:24:49 UTC (rev 53522)
@@ -431,7 +431,8 @@
 CVE-2017-11167 (FineCMS 2.1.0 allows remote attackers to execute arbitrary PHP code by ...)
 	NOT-FOR-US: FineCMS
 CVE-2017-11166 (The ReadXWDImage function in coders\xwd.c in ImageMagick 7.0.5-6 has a ...)
-	- imagemagick <unfixed> (low; bug #868263)
+	- imagemagick 8:6.9.7.4+dfsg-7 (low; bug #868263)
+	[jessie] - imagemagick 8:6.8.9.9-5+deb8u9
 	NOTE: https://github.com/ImageMagick/ImageMagick/issues/471
 CVE-2017-11165 (dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive ...)
 	NOT-FOR-US: dataTaker




More information about the Secure-testing-commits mailing list