[Secure-testing-commits] r52474 - data

Roberto C. Sanchez roberto at moszumanska.debian.org
Sat Jun 10 16:04:33 UTC 2017


Author: roberto
Date: 2017-06-10 16:04:33 +0000 (Sat, 10 Jun 2017)
New Revision: 52474

Modified:
   data/dla-needed.txt
Log:
Update status of imagemagick

Modified: data/dla-needed.txt
===================================================================
--- data/dla-needed.txt	2017-06-10 15:37:01 UTC (rev 52473)
+++ data/dla-needed.txt	2017-06-10 16:04:33 UTC (rev 52474)
@@ -18,8 +18,12 @@
   NOTE: Patch available, however not yet applied upstream.
 --
 imagemagick (Roberto C. Sánchez)
-  NOTE: CVE-2017-9262, CVE-2017-9405, CVE-2017-9406, CVE-2017-9407 are all leaks
-  NOTE: might be worth waiting until more issues pile up
+  NOTE: Fixes for CVE-2017-9261, CVE-2017-9262, CVE-2017-9405, CVE-2017-9407,
+  NOTE: CVE-2017-9409, CVE-2017-9439, CVE-2017-9500, and CVE-2017-9501 have been
+  NOTE: applied and pushed to the LTS Git repository for ImageMagick
+  NOTE: (https://anonscm.debian.org/git/collab-maint/debian-lts/imagemagick.git)
+  NOTE: CVE-2017-9440 and CVE-2017-9499 do not affect wheezy
+  NOTE: Once more issues appear or sufficient time has passed, I will upload
 --
 irssi
 --




More information about the Secure-testing-commits mailing list