Index: security/vuxml/vuln.xml =================================================================== --- security/vuxml/vuln.xml (revision 426137) +++ security/vuxml/vuln.xml (working copy) @@ -58,6 +58,46 @@ * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + ImageMagick7 -- multiple vulnerabilities + + + ImageMagick7 + 7.0.3.6 + + + ImageMagick7-nox11 + 7.0.3.6 + + + + +

Multiple sources report:

+
+

CVE-2016-9298: heap overflow in WaveletDenoiseImage(), fixed in ImageMagick7-7.0.3.6, discovered 2016-10-31

+
+
+

CVE-2016-8866: memory allocation failure in AcquireMagickMemory (incomplete previous fix for CVE-2016-8862), not fixed yet with the release of this announcement, re-discovered 2016-10-13.

+
+
+

CVE-2016-8862: memory allocation failure in AcquireMagickMemory, initially partially fixed in ImageMagick7-7.0.3.3, discovered 2016-09-14.

+
+ +
+ + https://github.com/ImageMagick/ImageMagick/issues/296 + https://blogs.gentoo.org/ago/2016/10/20/imagemagick-memory-allocation-failure-in-acquiremagickmemory-memory-c-incomplete-fix-for-cve-2016-8862/ + https://blogs.gentoo.org/ago/2016/10/17/imagemagick-memory-allocation-failure-in-acquiremagickmemory-memory-c/ + CVE-2016-9298 + CVE-2016-8866 + CVE-2016-8862 + + + 2016-09-14 + 2016-11-14 + +
+ lives -- insecure files permissions