Skip to content

[GHSA-5qr3-hm6r-fwx9] In MIFF image processing in ImageMagick before 7.1.1-44,... #5492

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Conversation

kbsteere
Copy link

Updates

  • Affected products
  • Description
  • References
  • Summary

Comments
Updating to enrichment information for legacy version 6.x.x-xx which this issue was also addressed in.

@github-actions github-actions bot changed the base branch from main to kbsteere/advisory-improvement-5492 April 29, 2025 20:52
@kbsteere
Copy link
Author

kbsteere commented Apr 29, 2025

The affected section was set to require for some reason. I've been unable to revert it.

Comment on lines +17 to +34
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": ""
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
]
}
],
Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": ""
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
]
}
],
"affected": [],

@JonathanLEvans
Copy link

Hi @kbsteere, thank you for your contribution. GitHub only reviews advisories in one of the supported ecosystems. Could you provide a link to where you found ImageMagick in one of the ecosystems?

@kbsteere
Copy link
Author

I didn't find it in that ecosystem. I used the gui to create this change and it wouldn't let me continue without adding an ecosystem. Don't know if it's a bug or some restriction for this GHSA. I created the suggested code change above because it should be an empty array since C/C++ is not a supported ecosystem.

@JonathanLEvans
Copy link

I am closing this request because it is out of scope. However, MITRE assigned the CVE ID so they can update the CVE record. You can contact MITRE through their webform at https://cveform.mitre.org/.

@github-actions github-actions bot deleted the kbsteere-GHSA-5qr3-hm6r-fwx9 branch April 30, 2025 21:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants