|
Message-ID: <20151008161044.7ea0d818@redhat.com>
Date: Thu, 8 Oct 2015 16:10:44 +0200
From: Stefan Cornelius <scorneli@...hat.com>
To: Seth Arnold <seth.arnold@...onical.com>
Cc: oss-security@...ts.openwall.com, security@...ntu.com
Subject: Re: CVE Request: ImageMagick
On Tue, 6 Oct 2015 21:38:11 -0700
Seth Arnold <seth.arnold@...onical.com> wrote:
> Hello MITRE, all,
>
>
> https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1448803
> Fix unknown.
>
Hi,
According to my analysis, there's a patch for this in the following
commit (the pict.c part):
https://github.com/ImageMagick/ImageMagick/commit/0f6fc2d5bf8f500820c3dbcf0d23ee14f2d9f734
Also, this is what I would classify as an integer truncation issue, not
a double-free.
Thanks,
--
Stefan Cornelius / Red Hat Product Security
Content of type "application/pgp-signature" skipped
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.