[Secure-testing-commits] r56004 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Fri Sep 22 09:15:14 UTC 2017


Author: carnil
Date: 2017-09-22 09:15:14 +0000 (Fri, 22 Sep 2017)
New Revision: 56004

Modified:
   data/CVE/list
Log:
Add CVE-2017-14684/imagemagick

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-09-22 09:14:11 UTC (rev 56003)
+++ data/CVE/list	2017-09-22 09:15:14 UTC (rev 56004)
@@ -33,7 +33,10 @@
 CVE-2017-14685 (Artifex MuPDF 1.11 allows attackers to cause a denial of service or ...)
 	TODO: check
 CVE-2017-14684 (In ImageMagick 7.0.7-4 Q16, a memory leak vulnerability was found in ...)
-	TODO: check
+	- imagemagick <unfixed> (unimportant)
+	NOTE: https://github.com/ImageMagick/ImageMagick/issues/770
+	NOTE: https://github.com/ImageMagick/ImageMagick/commit/dd367e0c3c3f37fbf1c20fa107b67a668b22c6e2
+	NOTE: ImageMagick-6: https://github.com/ImageMagick/ImageMagick/commit/a25142f284384a10306f14393d9bfd7af95ddfff
 CVE-2017-14683
 	RESERVED
 CVE-2017-14682 (GetNextToken in MagickCore/token.c in ImageMagick 7.0.6 allows remote ...)




More information about the Secure-testing-commits mailing list