[Git][security-tracker-team/security-tracker][master] Add CVE-2021-3574/imagemagick

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 29 06:09:46 BST 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e5c87ba3 by Salvatore Bonaccorso at 2022-08-29T07:09:15+02:00
Add CVE-2021-3574/imagemagick

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -84629,7 +84629,11 @@ CVE-2021-3575 (A heap-based buffer overflow was found in openjpeg in color.c:379
 	[stretch] - openjpeg2 <no-dsa> (Minor issue)
 	NOTE: https://github.com/uclouvain/openjpeg/issues/1347
 CVE-2021-3574 (A vulnerability was found in ImageMagick-7.0.11-5, where executing a c ...)
-	TODO: check
+	[experimental] - imagemagick 8:6.9.12.20+dfsg1-1
+	- imagemagick <unfixed>
+	NOTE: https://github.com/ImageMagick/ImageMagick/issues/3540
+	NOTE: https://github.com/ImageMagick/ImageMagick/commit/c6ad94fbb7b280f39c2fbbdc1c140e51b1b466e9
+	NOTE: https://github.com/ImageMagick/ImageMagick6/commit/cd7f9fb7751b0d59d5a74b12d971155caad5a792
 CVE-2021-33804
 	RESERVED
 CVE-2021-33803



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e5c87ba35502f7c269f222ec06255d1353e99f47

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e5c87ba35502f7c269f222ec06255d1353e99f47
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220829/25002d36/attachment.htm>


More information about the debian-security-tracker-commits mailing list