[Secure-testing-commits] r51328 - data/CVE

Moritz Muehlenhoff jmm at moszumanska.debian.org
Thu May 4 09:13:43 UTC 2017


Author: jmm
Date: 2017-05-04 09:13:43 +0000 (Thu, 04 May 2017)
New Revision: 51328

Modified:
   data/CVE/list
Log:
new imagemagick issue
NFUs


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-05-04 09:10:16 UTC (rev 51327)
+++ data/CVE/list	2017-05-04 09:13:43 UTC (rev 51328)
@@ -1,11 +1,11 @@
 CVE-2017-8776 (Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security ...)
-	TODO: check
+	NOT-FOR-US: Quick Heal Internet Security
 CVE-2017-8775 (Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security ...)
-	TODO: check
+	NOT-FOR-US: Quick Heal Internet Security
 CVE-2017-8774 (Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security ...)
-	TODO: check
+	NOT-FOR-US: Quick Heal Internet Security
 CVE-2017-8773 (Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security ...)
-	TODO: check
+	NOT-FOR-US: Quick Heal Internet Security
 CVE-2017-8772
 	RESERVED
 CVE-2017-8771
@@ -21,13 +21,15 @@
 CVE-2017-8766
 	RESERVED
 CVE-2017-8765 (The function named ReadICONImage in coders\icon.c in ImageMagick ...)
-	TODO: check
+	- imagemagick <unfixed> (low)
+	[jessie] - imagemagick <no-dsa> (Can be postponed until more severe issue are around)
+	NOTE: https://github.com/ImageMagick/ImageMagick/issues/466
 CVE-2017-8764
 	RESERVED
 CVE-2017-8763 (Cross-site scripting (XSS) vulnerability in ...)
-	TODO: check
+	NOT-FOR-US: EPESI
 CVE-2017-8762 (GeniXCMS 1.0.2 has XSS triggered by an authenticated user who submits a ...)
-	TODO: check
+	NOT-FOR-US: GenixCMS
 CVE-2017-8761
 	RESERVED
 CVE-2017-8760




More information about the Secure-testing-commits mailing list