summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorKoop Mast <kwm@FreeBSD.org>2017-05-30 10:26:21 +0000
committerKoop Mast <kwm@FreeBSD.org>2017-05-30 10:26:21 +0000
commit7400f000e033f8b2b40c29bc07ea7bf18e9ccfea (patch)
treef42a09e0cd1c2a5dd97db60c48a970991ebd8052
parentAdd a port of XkbInd, minimal keyboard layout indicator program. (diff)
Update imagemagick entry
* Fix indention * Add ranges to the imagemagick 6 version check, to prep for ImageMagick patch for the branch. * Add portepoch's to the imagemagick 6 versions. * Bump imagemagick 6 version. This version fixes at least one of the mentioned CVE's. * Change CVE-2017-8365 to CVE-2017-8765. CVE-2017-8365 is a libsndfile CVE. * Add modified tag.
Notes
Notes: svn path=/head/; revision=442056
-rw-r--r--security/vuxml/vuln.xml18
1 files changed, 10 insertions, 8 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml
index 8350151b1c23..359881c58c40 100644
--- a/security/vuxml/vuln.xml
+++ b/security/vuxml/vuln.xml
@@ -227,14 +227,15 @@ Notes:
<topic>ImageMagick -- multiple vulnerabilities</topic>
<affects>
<package>
- <name>ImageMagick</name>
- <name>ImageMagick-nox11</name>
- <range><lt>6.9.8.6</lt></range>
+ <name>ImageMagick</name>
+ <name>ImageMagick-nox11</name>
+ <range><lt>6.9.6.4_2,1</lt></range>
+ <range><ge>6.9.7.0,1</ge><lt>6.9.8.8,1</lt></range>
</package>
<package>
- <name>ImageMagick7</name>
- <name>ImageMagick7-nox11</name>
- <range><lt>7.0.5.9</lt></range>
+ <name>ImageMagick7</name>
+ <name>ImageMagick7-nox11</name>
+ <range><lt>7.0.5.9</lt></range>
</package>
</affects>
<description>
@@ -335,7 +336,7 @@ Notes:
to cause a denial of service (memory leak) via a crafted file.</li>
<li>CVE-2017-8357: ReadEPTImage function in ept.c allows attackers
to cause a denial of service (memory leak) via a crafted file.</li>
- <li>CVE-2017-8365: The function named ReadICONImage in coders\icon.c
+ <li>CVE-2017-8765: The function named ReadICONImage in coders\icon.c
has a memory leak vulnerability which can cause memory exhaustion
via a crafted ICON file.</li>
<li>CVE-2017-8830: ReadBMPImage function in bmp.c:1379 allows
@@ -392,7 +393,7 @@ Notes:
<cvename>CVE-2017-8355</cvename>
<cvename>CVE-2017-8356</cvename>
<cvename>CVE-2017-8357</cvename>
- <cvename>CVE-2017-8365</cvename>
+ <cvename>CVE-2017-8765</cvename>
<cvename>CVE-2017-8830</cvename>
<cvename>CVE-2017-9141</cvename>
<cvename>CVE-2017-9142</cvename>
@@ -402,6 +403,7 @@ Notes:
<dates>
<discovery>2017-03-05</discovery>
<entry>2017-05-25</entry>
+ <modified>2017-05-29</modified>
</dates>
</vuln>