[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Two imagemagick issues ignored

Moritz Muehlenhoff jmm at debian.org
Thu Jan 4 08:01:31 UTC 2018


Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
285364e3 by Moritz Muehlenhoff at 2018-01-04T09:01:13+01:00
Two imagemagick issues ignored

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -464,6 +464,8 @@ CVE-2017-1000477 (XMLBundle version 0.1.7 is vulnerable to XXE attacks which can
 	TODO: check
 CVE-2017-1000476 (ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability was found in ...)
 	- imagemagick <unfixed>
+	[stretch] - imagemagick <ignored> (Minor issue)
+	[jessie] - imagemagick <ignored> (Minor issue)
 	NOTE: https://github.com/ImageMagick/ImageMagick/issues/867
 	NOTE: ImageMagick-6: https://github.com/ImageMagick/ImageMagick/commit/e5dae180b9236bccd73ce93bfce81e99232a8533
 CVE-2017-1000473 (Linux Dash up to version v2 is vulnerable to multiple command ...)
@@ -2653,6 +2655,8 @@ CVE-2017-1000448 (Structured Data Linter versions 2.4.1 and older are vulnerable
 	TODO: check
 CVE-2017-1000445 (ImageMagick 7.0.7-1 and older version are vulnerable to null pointer ...)
 	- imagemagick <unfixed> (bug #886281)
+	[stretch] - imagemagick <ignored> (Minor issue)
+	[jessie] - imagemagick <ignored> (Minor issue)
 	NOTE: https://github.com/ImageMagick/ImageMagick/issues/775
 	NOTE: https://github.com/ImageMagick/ImageMagick/commit/441fde32557eb3cec573b0f877ac324173feed7f
 	NOTE: ImageMagick-6: https://github.com/ImageMagick/ImageMagick/commit/839a14e43d0c88db7b3fffe8aa4ec57d80c93623



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/285364e3f9b86fcc71097ad37994fab898dbee74

---
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/285364e3f9b86fcc71097ad37994fab898dbee74
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.alioth.debian.org/pipermail/secure-testing-commits/attachments/20180104/86f08494/attachment.html>


More information about the Secure-testing-commits mailing list