Bug#839827: freeimage: CVE-2016-5684

2016-10-06 Thread Ghislain Vaillant
Dear Salvatore, Balint, Thanks for forwarding the CVE to us and verifying which versions of the package were affected. I'll monitor the progress of this CVE. The CVE reporter offered some clues as to how to mitigate the problem, but I wonder how appropriate closure of this vulnerability can be v

Bug#839827: freeimage: CVE-2016-5684

2016-10-05 Thread Balint Reczey
Hi, On Wed, 05 Oct 2016 15:07:41 +0200 Salvatore Bonaccorso wrote: > Source: freeimage > Version: 3.17.0+ds1-2 > Severity: grave > Tags: security upstream > Justification: user security hole > > Hi, > > the following vulnerability was published for freeimage. > > CVE-2016-5684[0]: > XMP Image

Bug#839827: freeimage: CVE-2016-5684

2016-10-05 Thread Salvatore Bonaccorso
Source: freeimage Version: 3.17.0+ds1-2 Severity: grave Tags: security upstream Justification: user security hole Hi, the following vulnerability was published for freeimage. CVE-2016-5684[0]: XMP Image Handling Code Execution Vulnerability If you fix the vulnerability please also make sure to