oss-sec mailing list archives

RE: Update CVE-2021-3610


From: cpe_dictionary <cpe_dictionary () nist gov>
Date: Mon, 5 Jun 2023 14:35:15 +0000

Good morning,

Thank you for bringing this to our attention. We appreciate community input in order to provide the most accurate and 
up-to-date information as possible. After reviewing publicly available information we have made the appropriate 
modifications in addition to adding missing versions for the codebase. Please allow up to 24 hours for the changes to 
be reflected on the website and in the data feeds.

V/r,
Common Platform Enumeration Team
cpe_dictionary () nist gov

-----Original Message-----
From: Bastien Roucariès <rouca () debian org> 
Sent: Monday, May 29, 2023 1:21 PM
To: oss-security () lists openwall com
Cc: cpe_dictionary <cpe_dictionary () nist gov>
Subject: Update CVE-2021-3610

Hi,

I want to update status of CVE-2021-3610:

Contrary to common belief over the linux distribution this CVE affects imagemagick 6. It was introduced by commit 
b874d50070557eb98bdc6a3095ef4769af583dd2 for  6.9.10.88

Partial fixes:
Imagemagick6 <= 6.9.10-92 https://github.com/ImageMagick/ImageMagick6/commit/2d96228eec9fbea62ddb6c1450fa8d43e2c6b68a
Imagemagick6 <= 6.9.11-10 https://github.com/ImageMagick/ImageMagick6/commit/7374894385161859ffbb84e280fcc89e7ae257e4
ImageMagick6 <= 6.9.11-54 https://github.com/ImageMagick/ImageMagick6/commit/cdb67005376bcc8cbb0b743fb22787794cd30eb
ImageMagick6 [1/2]: https://github.com/ImageMagick/ImageMagick6/commit/b307bcadcdf6ea6819951ac1786b7904f27b25c6
Final fixes
ImageMagick6 [2/2]: https://github.com/ImageMagick/ImageMagick6/commit/c75ae771a00c38b757c5ef4b424b51e761b02552

I am not subscribed so cc me

Bastien

Current thread: