Debian Security Advisory

DLA-1000-1 imagemagick -- LTS security update

Date Reported:
24 Jun 2017
Affected Packages:
imagemagick
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 863833, Bug 863834, Bug 864087, Bug 864089, Bug 864090, Bug 864274.
In Mitre's CVE dictionary: CVE-2017-9261, CVE-2017-9262, CVE-2017-9405, CVE-2017-9407, CVE-2017-9409, CVE-2017-9439, CVE-2017-9500, CVE-2017-9501.
More information:

This update fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service if malformed MNG, JNG, ICON, PALM, MPC, or PDB files are processed.

For Debian 7 Wheezy, these problems have been fixed in version 8:6.7.7.10-5+deb7u15.

We recommend that you upgrade your imagemagick packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS