Debian Security Advisory

DLA-1131-1 imagemagick -- LTS security update

Date Reported:
11 Oct 2017
Affected Packages:
imagemagick
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 873871, Bug 875338, Bug 875339, Bug 875341, Bug 875352, Bug 875502, Bug 875503, Bug 875504.
In Mitre's CVE dictionary: CVE-2017-12691, CVE-2017-12692, CVE-2017-12693, CVE-2017-1287, CVE-2017-13758, CVE-2017-13768, CVE-2017-13769, CVE-2017-1406, CVE-2017-14172, CVE-2017-14173, CVE-2017-14174, CVE-2017-1417, CVE-2017-14224, CVE-2017-14249, CVE-2017-14341, CVE-2017-1440, CVE-2017-14505, CVE-2017-14607, CVE-2017-14682, CVE-2017-1473, CVE-2017-14741, CVE-2017-14989, CVE-2017-15016, CVE-2017-15017.
More information:

This updates fixes numerous vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure, or the execution of arbitrary code if malformed XCF, VIFF, BMP, thumbnail, CUT, PSD, TXT, XBM, PCX, MPC, WPG, TIFF, SVG, font, EMF, PNG, or other types of files are processed.

For Debian 7 Wheezy, these problems have been fixed in version 8:6.7.7.10-5+deb7u17.

We recommend that you upgrade your imagemagick packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS