[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 2366-1] imagemagick security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-2366-1               debian-lts@lists.debian.org
https://www.debian.org/lts/security/                     Markus Koschany
September 07, 2020                           https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : imagemagick
Version        : 8:6.9.7.4+dfsg-11+deb9u10
CVE ID         : CVE-2017-12140 CVE-2017-12429 CVE-2017-12430
        	 CVE-2017-12435 CVE-2017-12563 CVE-2017-12643
                 CVE-2017-12670 CVE-2017-12674 CVE-2017-12691
                 CVE-2017-12692 CVE-2017-12693 CVE-2017-12806
                 CVE-2017-12875 CVE-2017-13061 CVE-2017-13133
                 CVE-2017-13658 CVE-2017-13768 CVE-2017-14060
                 CVE-2017-14172 CVE-2017-14173 CVE-2017-14174
                 CVE-2017-14175 CVE-2017-14249 CVE-2017-14341
                 CVE-2017-14400 CVE-2017-14505 CVE-2017-14532
                 CVE-2017-14624 CVE-2017-14625 CVE-2017-14626
                 CVE-2017-14739 CVE-2017-14741 CVE-2017-15015
                 CVE-2017-15017 CVE-2017-15281 CVE-2017-17682
                 CVE-2017-17914 CVE-2017-18209 CVE-2017-18211
                 CVE-2017-18271 CVE-2017-18273 CVE-2017-1000445
                 CVE-2017-1000476 CVE-2018-16643 CVE-2018-16749
                 CVE-2018-18025 CVE-2019-11598 CVE-2019-13135
                 CVE-2019-13308 CVE-2019-13391 CVE-2019-15139

Debian Bug     : 870020 870019 876105 869727 886281 873059 870504
                 870530 870107 872609 875338 875339 875341 873871
                 873131 875352 878506 875503 875502 876105 876099
                 878546 878545 877354 877355 878524 878547 878548
                 878555 878554 878548 878555 878554 878579 885942
                 886584 928206 941670 931447 932079

Several security vulnerabilities were found in Imagemagick. Various
memory handling problems and cases of missing or incomplete input
sanitizing may result in denial of service, memory or CPU exhaustion,
information disclosure or potentially the execution of arbitrary code
when a malformed image file is processed.

For Debian 9 stretch, these problems have been fixed in version
8:6.9.7.4+dfsg-11+deb9u10.

We recommend that you upgrade your imagemagick packages.

For the detailed security status of imagemagick please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/imagemagick

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAl9WpRhfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD
RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQACgkQ2a0UuVE7
UeTl7w//fHuaM3bhEwCf4uMesNeGN0dv+fel55pr9WEZqAq+h8DdkKLefoWX5C9X
wQzKz9zDRZlnMXcdoZZJ3ddeSe1Zq2lZ03iw7ljUrbm6TCbrJw3WV+1Gl3jmRrK9
53VraTj7TnNmlJEx3yKx2CmtBn5dlZv52lfvtFLQHtgOif8NLJ/86C/8rCohKwlH
z3wMrFVLB+hpQgOpV9+Hh3QM4bq34KpPZsa/c7QXlC0yJCTyC/7K45/SsKwTdmzK
Cv4GyqPFoqKXMrK7fDwlfeGbclMz7qMqKBAv8alxKtsa+ayqSUoxfZcVQtU/03DS
ZSsxj/EPizIW+5B88SCyxxOefvumniqFr6Ox846upxqis41cAJ2dM9NXcLyrpV0R
aWzSwDiJjBf2AlzvHJm08LxIjkX6iGqy8z7sSIFnp4U8pi1yAFmovfoVUwAcrOFA
nejYUjzF9z6UyaBriXj42rZFhvC5+BZG9xA323VvAQzIHhGWnz/pmY4t99hh+aYD
VIJ0sjztcebfRYdJyxd2RrmQJE54KJOzz/RhXxYeDJNvOh6g8yX+PCylHyWv0TXD
Ut4AqA7SOp2FqG5vck119v4i+lrfkDbOeA8UHFeIJUUbQ9et4Nz8iIOZ226PrpH1
lghVrx9JlMyUgUl9uorMV8FFhgqH8v8hHD2WZ9CSL8iTsU/kZUA=
=kmXP
-----END PGP SIGNATURE-----


Reply to: