Debian Security Advisory

DLA-1081-1 imagemagick -- LTS security update

Date Reported:
31 Aug 2017
Affected Packages:
Security database references:
In the Debian bugtracking system: Bug 867367, Bug 867896, Bug 867806, Bug 867808, Bug 867810, Bug 867811, Bug 867812, Bug 867798.
In Mitre's CVE dictionary: CVE-2017-8352, CVE-2017-9144, CVE-2017-9501, CVE-2017-10928, CVE-2017-10995, CVE-2017-11141, CVE-2017-11170, CVE-2017-1118, CVE-2017-11352, CVE-2017-11360, CVE-2017-11446, CVE-2017-1144, CVE-2017-11449, CVE-2017-11450, CVE-2017-11478, CVE-2017-1150, CVE-2017-11523, CVE-2017-11524, CVE-2017-11525, CVE-2017-1152, CVE-2017-11527, CVE-2017-11528, CVE-2017-11529, CVE-2017-1153, CVE-2017-11531, CVE-2017-11532, CVE-2017-11533, CVE-2017-1153, CVE-2017-11535, CVE-2017-11537, CVE-2017-11539, CVE-2017-1163, CVE-2017-11640, CVE-2017-11644, CVE-2017-11724, CVE-2017-1175, CVE-2017-11752, CVE-2017-12140, CVE-2017-12418, CVE-2017-1242, CVE-2017-12428, CVE-2017-12429, CVE-2017-12430, CVE-2017-1243, CVE-2017-12432, CVE-2017-12433, CVE-2017-12435, CVE-2017-1256, CVE-2017-12564, CVE-2017-12565, CVE-2017-12566, CVE-2017-1258, CVE-2017-12640, CVE-2017-12641, CVE-2017-12642, CVE-2017-1264, CVE-2017-12654, CVE-2017-12664, CVE-2017-12665, CVE-2017-1266, CVE-2017-12670, CVE-2017-12674, CVE-2017-12675, CVE-2017-1267, CVE-2017-12877, CVE-2017-12983, CVE-2017-13133, CVE-2017-1313, CVE-2017-13139, CVE-2017-13142, CVE-2017-13143, CVE-2017-1314, CVE-2017-13146, CVE-2017-13658.
More information:

This updates fixes numerous vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed DPX, RLE, CIN, DIB, EPT, MAT, VST, PNG, JNG, MNG, DVJU, JPEG, TXT, PES, MPC, UIL, PS, PALM, CIP, TIFF, ICON, MAGICK, DCM, MSL, WMF, MIFF, PCX, SUN, PSD, MVG, PWP, PICT, PDB, SFW, or XCF files are processed.

For Debian 7 Wheezy, these problems have been fixed in version

We recommend that you upgrade your imagemagick packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: