Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ImageMagick6 NIST CPEs are stale #237

Open
MontyCarter opened this issue May 2, 2023 · 1 comment
Open

ImageMagick6 NIST CPEs are stale #237

MontyCarter opened this issue May 2, 2023 · 1 comment

Comments

@MontyCarter
Copy link

MontyCarter commented May 2, 2023

ImageMagick version

6.9.12-54 > version < 7.0.0-0

Operating system

Other (enter below)

Operating system, version and so on

N/A

Description

It seems that ImageMagick6 CPEs are no longer being added to the NIST cve database. The latest CPE is cpe:2.3:a:imagemagick:imagemagick:6.9.12-54:*:*:*:*:*:*:*, which was added on 06/30/2022 and last modified on 07/11/2022. It appears that the ImageMagick 7 CPEs are still being added: cpe:2.3:a:imagemagick:imagemagick:7.1.1-5:*:*:*:*:*:*:* was added on 03/28/23 and modified on 04/07/23.

This is problematic for tools that scan and alert for CVEs that are present in a project. For example, CVE-2023-1289 is listed as affecting cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* for all versions up to 7.1.1-0. This means that all versions of ImageMagick6 are flagged as being affected by this CVE, despite the fact that the ImageMagick 7 fix was ported over to ImageMagick6 (via a new commit commit rather than merging the ImageMagick7 fix), and included in 6.9.12-866.9.12-78

I'm wondering if this will be the state of things moving forward or whether this was an oversight.

Steps to Reproduce

Search for imagemagick 6.9.12-55+ in the NIST CPE database.

Images

No response

@urban-warrior
Copy link
Member

The ImageMagick team is not associated with nor does it maintain the NIST CPE database. You would need to contact the CPE maintainers to correct any deficiencies with the database.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

2 participants