[Git][security-tracker-team/security-tracker][master] CVE-2022-1325/cimg unfixed #1018941

Neil Williams (@codehelp) codehelp at debian.org
Fri Sep 2 09:51:03 BST 2022



Neil Williams pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f946b3bc by Neil Williams at 2022-09-02T09:50:41+01:00
CVE-2022-1325/cimg unfixed #1018941

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -27729,7 +27729,13 @@ CVE-2022-1327 (The Image Gallery WordPress plugin before 1.1.6 does not sanitize
 CVE-2022-1326 (The Form - Contact Form WordPress plugin through 1.2.0 does not saniti ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-1325 (A flaw was found in Clmg, where with the help of a maliciously crafted ...)
-	TODO: check
+	- cimg <unfixed> (bug #1018941)
+	NOTE: https://access.redhat.com/security/cve/CVE-2022-1325
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2074549
+	NOTE: https://github.com/GreycLab/CImg/commit/619cb58dd90b4e03ac68286c70ed98acbefd1c90 (v3.1.0)
+	NOTE: https://github.com/GreycLab/CImg/issues/343
+	NOTE: https://github.com/GreycLab/CImg/pull/348
+	NOTE: https://huntr.dev/bounties/a5e4fc45-8f14-4dd1-811b-740fc50c95d2/
 CVE-2022-1324 (The Event Timeline WordPress plugin through 1.1.5 does not sanitize an ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-1323 (The Discy WordPress theme before 5.0 lacks authorization checks then p ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f946b3bc56747c2ec0390e1c8af268b677e5caab

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f946b3bc56747c2ec0390e1c8af268b677e5caab
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220902/5f05ab4c/attachment.htm>


More information about the debian-security-tracker-commits mailing list