[Git][security-tracker-team/security-tracker][master] CVE-2023-2157/imagemagick
Bastien Roucariès (@rouca)
rouca at debian.org
Sun Mar 17 13:35:18 GMT 2024
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker
Commits:
fcd73685 by Bastien Roucariès at 2024-03-17T13:34:38+00:00
CVE-2023-2157/imagemagick
Code was introduce post trixie
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -53504,9 +53504,9 @@ CVE-2023-2158 (Code Dx versions prior to 2023.4.2 are vulnerable to user imperso
NOT-FOR-US: Code Dx
CVE-2023-2157 (A heap-based buffer overflow vulnerability was found in the ImageMagic ...)
- imagemagick 8:6.9.12.98+dfsg1-2 (bug #1036476)
- [bookworm] - imagemagick <no-dsa> (Minor issue)
- [bullseye] - imagemagick <no-dsa> (Minor issue)
- [buster] - imagemagick <no-dsa> (Minor issue)
+ [bookworm] - imagemagick <not-affected> (Vulnerable code was introduced later)
+ [bullseye] - imagemagick <not-affected> (Vulnerable code was introduced later)
+ [buster] - imagemagick <not-affected> (Vulnerable code was introduced later)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/9a9896fce95d09e5e47b86baccbe1ce1a2fca76b (7.1.1-7)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/7e4c992f148afc5b28111e540921d5b6e4e38673 (6.9.12-85)
CVE-2023-2156 (A flaw was found in the networking subsystem of the Linux kernel withi ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fcd73685be2e57f6802681cec476ae6c68807bb8
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fcd73685be2e57f6802681cec476ae6c68807bb8
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240317/fe498d16/attachment.htm>
More information about the debian-security-tracker-commits
mailing list