[Git][security-tracker-team/security-tracker][master] 2 commits: Add CVE-2018-10805/imagemagick
Salvatore Bonaccorso
carnil at debian.org
Tue May 8 21:24:27 BST 2018
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
13b1ca5a by Salvatore Bonaccorso at 2018-05-08T22:20:59+02:00
Add CVE-2018-10805/imagemagick
- - - - -
439775e3 by Salvatore Bonaccorso at 2018-05-08T22:24:05+02:00
Add bug referene for CVE-2018-10804
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -15,9 +15,10 @@ CVE-2018-10807
CVE-2018-10806 (An issue was discovered in Frog CMS 0.9.5. There is a reflected Cross ...)
NOT-FOR-US: Frog CMS
CVE-2018-10805 (ImageMagick version 7.0.7-28 contains a memory leak in ReadYCBCRImage ...)
- TODO: check
-CVE-2018-10804 (ImageMagick version 7.0.7-28 contains a memory leak in WriteTIFFImage ...)
- imagemagick <unfixed> (unimportant)
+ NOTE: https://github.com/ImageMagick/ImageMagick/issues/1054
+CVE-2018-10804 (ImageMagick version 7.0.7-28 contains a memory leak in WriteTIFFImage ...)
+ - imagemagick <unfixed> (unimportant; bug #898217)
NOTE: https://github.com/ImageMagick/ImageMagick/issues/1053
NOTE: https://github.com/ImageMagick/ImageMagick/commit/052f6c22d3a2b2aae9dfa24aff9ccdf8b72ace91
CVE-2018-10803
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/ac1ef7ffd80d1f51b18c422fb99c0718e3ce4c42...439775e3cd365ebc3c515ecb4aa85f44d3701853
---
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/compare/ac1ef7ffd80d1f51b18c422fb99c0718e3ce4c42...439775e3cd365ebc3c515ecb4aa85f44d3701853
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20180508/3a238b3c/attachment.html>
More information about the debian-security-tracker-commits
mailing list