~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
Candidate: CVE-2016-10068
PublicDate: 2017-03-02
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10068
 https://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=30797
 http://www.openwall.com/lists/oss-security/2016/12/20/3
Description:
 The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers
 to cause a denial of service (segmentation fault and application crash) via
 a crafted XML file.
Ubuntu-Description:
Notes:
 mdeslaur> This is 0165-Prevent-fault-in-MSL-interpreter.patch
Bugs:
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=845241
Priority: medium
Discovered-by:
Assigned-to:

Patches_imagemagick:
 upstream: https://github.com/ImageMagick/ImageMagick/commit/56d6e20de489113617cbbddaf41e92600a34db22
upstream_imagemagick: released (8:6.9.6.5+dfsg-1)
precise_imagemagick: released (8:6.6.9.7-5ubuntu3.6)
trusty_imagemagick: released (8:6.7.7.10-6ubuntu3.3)
vivid/stable-phone-overlay_imagemagick: DNE
vivid/ubuntu-core_imagemagick: DNE
xenial_imagemagick: released (8:6.8.9.9-7ubuntu5.3)
yakkety_imagemagick: released (8:6.8.9.9-7ubuntu8.2)
devel_imagemagick: not-affected (8:6.9.6.6+dfsg-1ubuntu3)