Debian Security Advisory
DSA-3863-1 imagemagick -- security update
- Date Reported:
- 25 May 2017
- Affected Packages:
- imagemagick
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 860736, Bug 862577, Bug 859771, Bug 859769, Bug 860734, Bug 862572, Bug 862574, Bug 862573.
In Mitre's CVE dictionary: CVE-2017-7606, CVE-2017-7619, CVE-2017-7941, CVE-2017-7943, CVE-2017-8343, CVE-2017-8344, CVE-2017-8345, CVE-2017-8346, CVE-2017-8347, CVE-2017-8348, CVE-2017-8349, CVE-2017-8350, CVE-2017-8351, CVE-2017-8352, CVE-2017-8353, CVE-2017-8354, CVE-2017-8355, CVE-2017-8356, CVE-2017-8357, CVE-2017-8765, CVE-2017-8830, CVE-2017-9098, CVE-2017-9141, CVE-2017-9142, CVE-2017-9143, CVE-2017-9144. - More information:
-
This update fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed RLE, ART, JNG, DDS, BMP, ICO, EPT, SUN, MTV, PICT, XWD, PCD, SFW, MAT, EXR, DCM, MNG, PCX or SVG files are processed.
For the stable distribution (jessie), these problems have been fixed in version 8:6.8.9.9-5+deb8u9.
For the upcoming stable distribution (stretch), these problems have been fixed in version 8:6.9.7.4+dfsg-8.
For the unstable distribution (sid), these problems have been fixed in version 8:6.9.7.4+dfsg-8.
We recommend that you upgrade your imagemagick packages.