Bug#849439: imagemagick: CVE-2016-10062: fwrite issue in ReadGROUP4Image

2016-12-27 Thread Salvatore Bonaccorso
Hi Bastien, On Tue, Dec 27, 2016 at 11:42:12PM +0100, Bastien ROUCARIES wrote: > I suppose experimental version is immune ? Just checked. AFAICT, as well in version 8:6.9.7.0+dfsg-1 as right now in experimental, there is still no error handling for the fwrite's in ReadGROUP4Image. I added a

Bug#849439: imagemagick: CVE-2016-10062: fwrite issue in ReadGROUP4Image

2016-12-27 Thread Bastien ROUCARIES
I suppose experimental version is immune ? On Tue, Dec 27, 2016 at 8:42 AM, Salvatore Bonaccorso wrote: > Source: imagemagick > Version: 8:6.8.9.9-5 > Severity: important > Tags: upstream security > > Hi, > > the following vulnerability was published for imagemagick. AFAICT, >

Bug#849439: imagemagick: CVE-2016-10062: fwrite issue in ReadGROUP4Image

2016-12-26 Thread Salvatore Bonaccorso
Source: imagemagick Version: 8:6.8.9.9-5 Severity: important Tags: upstream security Hi, the following vulnerability was published for imagemagick. AFAICT, this is not yet fixed up to the version in unstable. the CVE assignment is at[1] and reads as: > > Check return of write function > >