- -------------------------------------------------------------------------
Debian LTS Advisory DLA-2366-1               debian-lts@lists.debian.org
https://www.debian.org/lts/security/                     Markus Koschany
September 07, 2020                           https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : imagemagick
Version        : 8:6.9.7.4+dfsg-11+deb9u10
CVE ID         : CVE-2017-12140 CVE-2017-12429 CVE-2017-12430
        	 CVE-2017-12435 CVE-2017-12563 CVE-2017-12643
                 CVE-2017-12670 CVE-2017-12674 CVE-2017-12691
                 CVE-2017-12692 CVE-2017-12693 CVE-2017-12806
                 CVE-2017-12875 CVE-2017-13061 CVE-2017-13133
                 CVE-2017-13658 CVE-2017-13768 CVE-2017-14060
                 CVE-2017-14172 CVE-2017-14173 CVE-2017-14174
                 CVE-2017-14175 CVE-2017-14249 CVE-2017-14341
                 CVE-2017-14400 CVE-2017-14505 CVE-2017-14532
                 CVE-2017-14624 CVE-2017-14625 CVE-2017-14626
                 CVE-2017-14739 CVE-2017-14741 CVE-2017-15015
                 CVE-2017-15017 CVE-2017-15281 CVE-2017-17682
                 CVE-2017-17914 CVE-2017-18209 CVE-2017-18211
                 CVE-2017-18271 CVE-2017-18273 CVE-2017-1000445
                 CVE-2017-1000476 CVE-2018-16643 CVE-2018-16749
                 CVE-2018-18025 CVE-2019-11598 CVE-2019-13135
                 CVE-2019-13308 CVE-2019-13391 CVE-2019-15139

Debian Bug     : 870020 870019 876105 869727 886281 873059 870504
                 870530 870107 872609 875338 875339 875341 873871
                 873131 875352 878506 875503 875502 876105 876099
                 878546 878545 877354 877355 878524 878547 878548
                 878555 878554 878548 878555 878554 878579 885942
                 886584 928206 941670 931447 932079

Several security vulnerabilities were found in Imagemagick. Various
memory handling problems and cases of missing or incomplete input
sanitizing may result in denial of service, memory or CPU exhaustion,
information disclosure or potentially the execution of arbitrary code
when a malformed image file is processed.

For Debian 9 stretch, these problems have been fixed in version
8:6.9.7.4+dfsg-11+deb9u10.

We recommend that you upgrade your imagemagick packages.

For the detailed security status of imagemagick please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/imagemagick

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-2366-1: imagemagick security update

September 7, 2020
Debian Bug : 870020 870019 876105 869727 886281 873059 870504 870530 870107 872609 875338 875339 875341 873871 873131 875352 878506 875503 875502 876105 876099 878546 878545 877354...

Summary

Several security vulnerabilities were found in Imagemagick. Various
memory handling problems and cases of missing or incomplete input
sanitizing may result in denial of service, memory or CPU exhaustion,
information disclosure or potentially the execution of arbitrary code
when a malformed image file is processed.

For Debian 9 stretch, these problems have been fixed in version
8:6.9.7.4+dfsg-11+deb9u10.

We recommend that you upgrade your imagemagick packages.

For the detailed security status of imagemagick please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/imagemagick

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
Package : imagemagick
Version : 8:6.9.7.4+dfsg-11+deb9u10
CVE ID : CVE-2017-12140 CVE-2017-12429 CVE-2017-12430
Debian Bug : 870020 870019 876105 869727 886281 873059 870504

Related News