Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Debian DSA-4640-1: Critical Graphicsmagick DoS and Memory Issues

debian
Calendar Grey March 15, 2020
Debian Logo
This notification outlines an essential safety enhancement for ImageMagick that tackles several memory management vulnerabilities.
This update fixes several vulnerabilities in Graphicsmagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, m...

Summary

This update fixes several vulnerabilities in Graphicsmagick: Various memory
handling problems and cases of missing or incomplete input sanitising
may result in denial of service, memory disclosure or the execution
of arbitrary code if malformed media files are processed.

For the oldstable distribution (stretch), these problems have been fixed
in version 1.3.30+hg15796-1~deb9u3.

For the stable distribution (buster), these problems have been fixed in
version 1.4~hg15978-1+deb10u1.

We recommend that you upgrade your graphicsmagick packages.

For the detailed security status of graphicsmagick please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/graphicsmagick

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: graphicsmagick
CVE ID: CVE-2019-19950 CVE-2019-19951 CVE-2019-19953 CVE-2019-11474

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here