[Secure-testing-commits] r53808 - in data: CVE DSA

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sun Jul 23 06:04:43 UTC 2017


Author: carnil
Date: 2017-07-23 06:04:43 +0000 (Sun, 23 Jul 2017)
New Revision: 53808

Modified:
   data/CVE/list
   data/DSA/list
Log:
CVE-2017-11526 assigned for #867825

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-07-23 06:03:26 UTC (rev 53807)
+++ data/CVE/list	2017-07-23 06:04:43 UTC (rev 53808)
@@ -499,10 +499,8 @@
 	{DSA-3914-1}
 	- imagemagick 8:6.9.7.4+dfsg-12 (bug #867826)
 	NOTE: https://github.com/ImageMagick/ImageMagick/issues/528
-CVE-2017-XXXX [CPU exhaustion in ReadOneMNGImage]
+CVE-2017-11526 [CPU exhaustion in ReadOneMNGImage]
 	- imagemagick 8:6.9.7.4+dfsg-12 (bug #867825)
-	[stretch] - imagemagick 8:6.9.7.4+dfsg-11+deb9u1
-	[jessie] - imagemagick 8:6.8.9.9-5+deb8u10
 	NOTE: https://github.com/ImageMagick/ImageMagick/issues/527
 CVE-2017-11505 (The ReadOneJNGImage function in coders/png.c in ImageMagick through ...)
 	{DSA-3914-1}

Modified: data/DSA/list
===================================================================
--- data/DSA/list	2017-07-23 06:03:26 UTC (rev 53807)
+++ data/DSA/list	2017-07-23 06:04:43 UTC (rev 53808)
@@ -6,7 +6,7 @@
 	{CVE-2017-1000026}
 	[stretch] - ruby-mixlib-archive 0.2.0-1+deb9u1
 [18 Jul 2017] DSA-3914-1 imagemagick - security update
-	{CVE-2017-9439 CVE-2017-9440 CVE-2017-9501 CVE-2017-10928 CVE-2017-11141 CVE-2017-11170 CVE-2017-11188 CVE-2017-11360 CVE-2017-11449 CVE-2017-11448 CVE-2017-11447 CVE-2017-11450 CVE-2017-11478 CVE-2017-11505 CVE-2017-11524 CVE-2017-11525}
+	{CVE-2017-9439 CVE-2017-9440 CVE-2017-9501 CVE-2017-10928 CVE-2017-11141 CVE-2017-11170 CVE-2017-11188 CVE-2017-11360 CVE-2017-11449 CVE-2017-11448 CVE-2017-11447 CVE-2017-11450 CVE-2017-11478 CVE-2017-11505 CVE-2017-11524 CVE-2017-11525 CVE-2017-11526}
 	[jessie] - imagemagick 8:6.8.9.9-5+deb8u10
 	[stretch] - imagemagick 8:6.9.7.4+dfsg-11+deb9u1
 [18 Jul 2017] DSA-3913-1 apache2 - security update




More information about the Secure-testing-commits mailing list