diff options
author | Koop Mast <kwm@FreeBSD.org> | 2017-05-30 10:26:21 +0000 |
---|---|---|
committer | Koop Mast <kwm@FreeBSD.org> | 2017-05-30 10:26:21 +0000 |
commit | 7400f000e033f8b2b40c29bc07ea7bf18e9ccfea (patch) | |
tree | f42a09e0cd1c2a5dd97db60c48a970991ebd8052 | |
parent | Add a port of XkbInd, minimal keyboard layout indicator program. (diff) |
Update imagemagick entry
* Fix indention
* Add ranges to the imagemagick 6 version check, to prep for
ImageMagick patch for the branch.
* Add portepoch's to the imagemagick 6 versions.
* Bump imagemagick 6 version. This version fixes at least one of
the mentioned CVE's.
* Change CVE-2017-8365 to CVE-2017-8765. CVE-2017-8365 is a
libsndfile CVE.
* Add modified tag.
Notes
Notes:
svn path=/head/; revision=442056
-rw-r--r-- | security/vuxml/vuln.xml | 18 |
1 files changed, 10 insertions, 8 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 8350151b1c23..359881c58c40 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -227,14 +227,15 @@ Notes: <topic>ImageMagick -- multiple vulnerabilities</topic> <affects> <package> - <name>ImageMagick</name> - <name>ImageMagick-nox11</name> - <range><lt>6.9.8.6</lt></range> + <name>ImageMagick</name> + <name>ImageMagick-nox11</name> + <range><lt>6.9.6.4_2,1</lt></range> + <range><ge>6.9.7.0,1</ge><lt>6.9.8.8,1</lt></range> </package> <package> - <name>ImageMagick7</name> - <name>ImageMagick7-nox11</name> - <range><lt>7.0.5.9</lt></range> + <name>ImageMagick7</name> + <name>ImageMagick7-nox11</name> + <range><lt>7.0.5.9</lt></range> </package> </affects> <description> @@ -335,7 +336,7 @@ Notes: to cause a denial of service (memory leak) via a crafted file.</li> <li>CVE-2017-8357: ReadEPTImage function in ept.c allows attackers to cause a denial of service (memory leak) via a crafted file.</li> - <li>CVE-2017-8365: The function named ReadICONImage in coders\icon.c + <li>CVE-2017-8765: The function named ReadICONImage in coders\icon.c has a memory leak vulnerability which can cause memory exhaustion via a crafted ICON file.</li> <li>CVE-2017-8830: ReadBMPImage function in bmp.c:1379 allows @@ -392,7 +393,7 @@ Notes: <cvename>CVE-2017-8355</cvename> <cvename>CVE-2017-8356</cvename> <cvename>CVE-2017-8357</cvename> - <cvename>CVE-2017-8365</cvename> + <cvename>CVE-2017-8765</cvename> <cvename>CVE-2017-8830</cvename> <cvename>CVE-2017-9141</cvename> <cvename>CVE-2017-9142</cvename> @@ -402,6 +403,7 @@ Notes: <dates> <discovery>2017-03-05</discovery> <entry>2017-05-25</entry> + <modified>2017-05-29</modified> </dates> </vuln> |