[Secure-testing-commits] r56685 - data/CVE
Salvatore Bonaccorso
carnil at moszumanska.debian.org
Sat Oct 14 09:27:17 UTC 2017
Author: carnil
Date: 2017-10-14 09:27:17 +0000 (Sat, 14 Oct 2017)
New Revision: 56685
Modified:
data/CVE/list
Log:
Add bug references for three imagemagick issues
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2017-10-14 09:22:49 UTC (rev 56684)
+++ data/CVE/list 2017-10-14 09:27:17 UTC (rev 56685)
@@ -3523,7 +3523,7 @@
NOTE: https://gitlab.com/libidn/libidn2/commit/16853b6973a1e72fee2b7cccda85472cb9951305
CVE-2017-14060 (In ImageMagick 7.0.6-10, a NULL Pointer Dereference issue is present in ...)
{DLA-1131-1}
- - imagemagick <unfixed>
+ - imagemagick <unfixed> (bug #878506)
NOTE: https://github.com/ImageMagick/ImageMagick/issues/710
NOTE: https://github.com/ImageMagick/ImageMagick/commit/c535e1f1a6b1faaa35e007df4fc535ec08daa97c
NOTE: ImageMagick-6: https://github.com/ImageMagick/ImageMagick/commit/5bdfef29f5e6744f36f25ec04583c6b6f4a13b48
@@ -4156,7 +4156,7 @@
RESERVED
CVE-2017-13769 (The WriteTHUMBNAILImage function in coders/thumbnail.c in ImageMagick ...)
{DLA-1131-1}
- - imagemagick <unfixed> (low)
+ - imagemagick <unfixed> (low; bug #878507)
NOTE: https://github.com/ImageMagick/ImageMagick/issues/705
NOTE: https://github.com/ImageMagick/ImageMagick/commit/45d342155b5e9b83904c695411d20f33cf9b524c
NOTE: ImageMagick-6: https://github.com/ImageMagick/ImageMagick/commit/457e63263de6f732785608504b6e607799ad3dd5
@@ -4204,7 +4204,7 @@
RESERVED
CVE-2017-13758 (In ImageMagick 7.0.6-10, there is a heap-based buffer overflow in the ...)
{DLA-1131-1}
- - imagemagick <unfixed>
+ - imagemagick <unfixed> (bug #878508)
NOTE: https://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=32583
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/ef6cee1bcf144b7c9285787920361a53296e7907
NOTE: ImageMagick-6: https://github.com/ImageMagick/ImageMagick/commit/57eced684ad0660fe580800d977ba94623ec67ac
More information about the Secure-testing-commits
mailing list