Package : vips Version : 7.28.5-1+deb7u2 CVE ID : CVE-2018-7998 Debian Bug : #892589 It was discovered that there was NULL function pointer dereference vulnerability in vips, an image processing system for very large images. Remote attackers could cause a denial of service via a specially-crafted image file which occurred due to a race condition involving a failed image load and other worker threads. For Debian 7 "Wheezy", this issue has been fixed in vips version 7.28.5-1+deb7u2. We recommend that you upgrade your vips packages. Regards, - -- ,''`. : :' : Chris Lamb `. `'` lamby@debian.org / chris-lamb.co.uk `-