[Pkg-gmagick-im-team] Bug#845206: CVE-2016-8677: memory allocate failure in AcquireQuantumPixels

Salvatore Bonaccorso carnil at debian.org
Mon Nov 21 13:19:49 UTC 2016


Hi,

On Mon, Nov 21, 2016 at 01:51:52PM +0100, Bastien ROUCARIES wrote:
> Package: src:imagemagick
> version: 8:6.9.6.2+dfsg-2
> Severity: important
> Tags: patch security
> X-Debbugs-CC: secure-testing-team at lists.alioth.debian.org
> control: found -1 8:6.7.7.10-5+deb7u7
> control: found -1 8:6.8.9.9-5+deb8u5
> control: tags -1 + fixed-upstream
> 
> 
> https://blogs.gentoo.org/ago/2016/10/07/imagemagick-memory-allocate-failure-in-acquirequantumpixels-quantum-c/
> Fixed by: https://github.com/ImageMagick/ImageMagick/commit/6e48aa92ff4e6e95424300ecd52a9ea453c19c60

Isn't this fixed already in 8:6.9.6.2+dfsg-1? What do I miss?

Regards,
Salvatore



More information about the Pkg-gmagick-im-team mailing list