[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 1968-1] imagemagick security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Package        : imagemagick
Version        : 8:6.8.9.9-5+deb8u18
CVE ID         : CVE-2019-11470 CVE-2019-14981 CVE-2019-15139 CVE-2019-15140

Multiple vulnerabilities have been found in imagemagick, an image processing
toolkit.

CVE-2019-11470

    Uncontrolled resource consumption caused by insufficiently sanitized image
    size in ReadCINImage (coders/cin.c). This vulnerability might be leveraged
    by remote attackers to cause denial of service via a crafted Cineon image.

CVE-2019-14981

    Divide-by-zero vulnerability in MeanShiftImage (magick/feature.c). This
    vulnerability might be leveraged by remote attackers to cause denial of
    service via crafted image data.

CVE-2019-15139

    Out-of-bounds read in ReadXWDImage (coders/xwd.c). This vulnerability might
    be leveraged by remote attackers to cause denial of service via a crafted
    XWD (X Window System window dumping file) image file.

CVE-2019-15140

    Bound checking issue in ReadMATImage (coders/mat.c), potentially leading to
    use-after-free. This vulnerability might be leveraged by remote attackers to
    cause denial of service or any other unspecified impact via a crafted MAT
    image file.

For Debian 8 "Jessie", these problems have been fixed in version
8:6.8.9.9-5+deb8u18.

We recommend that you upgrade your imagemagick packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQGzBAEBCgAdFiEEeDb9QWtkMa2LX4zREeMFjl5EGkIFAl2tdIcACgkQEeMFjl5E
GkKTPwwAqtQhPT+Fko3ii29cesbysIQguLqqm7u2rhVGPzGSa2HWdRa0U/Cr+xlQ
SKXpQkAYIlX7laXJO4qQupYEC/rYabhL+MzTe+YNHFe7hQlGLfS+8B7alIMdOc4Y
sOGZ0l/utplAT2ms4OFz6wY/h8iCAIVkgtMG5etmcx9DHLjN5kUb8+JfnGjuxQ7E
1iRK9ZGFkk82MRyB2E/HgrOHFOeLDiwUyQeRisrNTNf/yt+Sy88MXFCJ1AEQvWSl
Q8oztTRxw3yKxXyn3AiBm6vR/8f41YJR6hL9MdX8cfQ/HWgMLqTqsTgcjYCeGVM1
gWjlbxWDC6Ym12opo5epO6T0fXi6NHNJtyNuiHOHg1ieZVRD5d2OIhNxxv9xFhI8
5FVUJ7IjEioNopYYOFq3AvhI20aW2VuUMTBuLuWpoYsE5J2DbNpaSX82EsBQbI8J
1jqSFY99W8cyKnq2xdD3MVyHlcrMdS/Ubf38zfFRTzXup95zGdDhqkuQkl1kEyOY
nPXApiw4
=bf8B
-----END PGP SIGNATURE-----


Reply to: