From a2a40c8989351ad6020a332a94a803e95b51cd1e Mon Sep 17 00:00:00 2001 From: Mark Felder Date: Sat, 4 Feb 2017 17:21:09 +0000 Subject: Document freeimage vulnerability PR: 216657 Security: CVE-2016-5684 --- security/vuxml/vuln.xml | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) (limited to 'security') diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index aac1bf5217f8..febf28a6c26d 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -58,6 +58,34 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + freeimage -- code execution vulnerability + + + freeimage + 0 + + + + +

TALOS reports:

+
+

An exploitable out-of-bounds write vulnerability exists in + the XMP image handling functionality of the FreeImage library.

+
+ +
+ + http://www.talosintelligence.com/reports/TALOS-2016-0189/ + CVE-2016-5684 + ports/216657 + + + 2016-10-03 + 2017-02-04 + +
+ shotwell -- failure to encrypt authentication -- cgit v1.2.3