[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 3429-1] imagemagick security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-3429-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                    Bastien Roucaries
May 21, 2023                                  https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : imagemagick
Version        : 8:6.9.10.23+dfsg-2.1+deb10u5
CVE ID         : CVE-2021-20176 CVE-2021-20241 CVE-2021-20243 CVE-2021-20244 
                 CVE-2021-20245 CVE-2021-20246 CVE-2021-20309 CVE-2021-20312 
                 CVE-2021-20313 CVE-2021-39212 CVE-2022-28463 CVE-2022-32545 
                 CVE-2022-32546 CVE-2022-32547
Debian Bug     : 996588 1013282 1016442

Multiple vulnerabilities were fixed in imagemagick, a software suite,
used for editing and manipulating digital images.

CVE-2021-20176

    A divide by zero was found in gem.c file.

CVE-2021-20241

    A divide by zero was found in  jp2 coder.

CVE-2021-20243

    A divide by zero was found in dcm coder.

CVE-2021-20244

    A divide by zero was found in fx.c.

CVE-2021-20245

    A divide by zero was found in webp coder.

CVE-2021-20246

    A divide by zero was found in resample.c.

CVE-2021-20309

    A divide by zero was found in WaveImage.c

CVE-2021-20312

    An integer overflow was found in WriteTHUMBNAILImage()
    of coders/thumbnail.c

CVE-2021-20313

    A potential cipher leak was found when the calculate
    signatures in TransformSignature().

CVE-2021-39212

    A policy bypass was found for postscript files.

CVE-2022-28463

    A bufer overflow was found in  buffer overflow in cin coder.

CVE-2022-32545

    A undefined behavior (conversion outside the range of
    representable values of type 'unsigned char') was found in psd
    file handling.

CVE-2022-32546

    A undefined behavior (conversion outside the range of
    representable values of type 'long') was found in pcl
    file handling.

CVE-2022-32547

    An unaligned access was found in property.c

For Debian 10 buster, these problems have been fixed in version
8:6.9.10.23+dfsg-2.1+deb10u5.

We recommend that you upgrade your imagemagick packages.

For the detailed security status of imagemagick please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/imagemagick

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmRqmVMACgkQADoaLapB
CF8kRg/7BM6uzmf+carUUMDzTBep32H0bkjAc4rSKaLT6CW5q9AGplSijEGsL+2n
sWK3Y3x8pPaaTXIOV+Xx0vDTl9isxF4r6cyckp+Pziz8bSPTd50r0IgzKZP0k57r
YH/Z5VpP59BWAsNCIiaybi65+avf/00kw2CWZ08feC1vV2LmQUp5wDmwA3z/8E9P
PiZ2gVOoc1aTKzUgGkGJPoiCeaAJl8cvSwUH4txXPDTbtv0gjFVVxfLmB7nnWc5b
QWTo4MOoowRORdGPtFIjgkozdDMA1toHK/8fPB2ke/N0lBXjivFwsUiqMb1jAgjt
OkVzqfwk/Plm2KvwGLAjn6dTH2dvAueNovX1jcbIdEeWZuIqooydaLdEgE8/OLBm
GlvIN+hIZkWBW7F0Wa0WuVj2sgdO3dBdlKi2dqmq9qBMcc4IxLJiP0sRxaegf/JN
Sg8SU288p2C9uBR6AqPXCqFIGl8MqoB9nTqpebHSpzXFGJTb52NQArV/1zjDZGXR
voMkPrZuRd0sp7jxpKT5dQbhxT+zCL7XpeiMCUCCh0mAeTT4SMQTyJVtlcgLCibx
fWtFYu9L3yZUjnXTBmI7Bfvn/EMwhilYH7NtF0jyves7erMFBifaKN2riosW7jTL
aZovpK9R+i0r3PJA9UUhZZYM161jafMRQ6bwBPOgGDL/2K+ZxlY=
=eYBc
-----END PGP SIGNATURE-----


Reply to: