Debian Security Advisory
DLA-1131-1 imagemagick -- LTS security update
- Date Reported:
- 11 Oct 2017
- Affected Packages:
- imagemagick
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 873871, Bug 875338, Bug 875339, Bug 875341, Bug 875352, Bug 875502, Bug 875503, Bug 875504.
In Mitre's CVE dictionary: CVE-2017-12691, CVE-2017-12692, CVE-2017-12693, CVE-2017-1287, CVE-2017-13758, CVE-2017-13768, CVE-2017-13769, CVE-2017-1406, CVE-2017-14172, CVE-2017-14173, CVE-2017-14174, CVE-2017-1417, CVE-2017-14224, CVE-2017-14249, CVE-2017-14341, CVE-2017-1440, CVE-2017-14505, CVE-2017-14607, CVE-2017-14682, CVE-2017-1473, CVE-2017-14741, CVE-2017-14989, CVE-2017-15016, CVE-2017-15017. - More information:
-
This updates fixes numerous vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure, or the execution of arbitrary code if malformed XCF, VIFF, BMP, thumbnail, CUT, PSD, TXT, XBM, PCX, MPC, WPG, TIFF, SVG, font, EMF, PNG, or other types of files are processed.
For Debian 7
Wheezy
, these problems have been fixed in version 8:6.7.7.10-5+deb7u17.We recommend that you upgrade your imagemagick packages.
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS