Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 28 articles for you...
172

Ubuntu ImageMagick Serious Buffer Overflow DoS Vulnerability USN-8468-1

Several security issues were fixed in ImageMagick.. ========================================================================== Ubuntu Security Notice USN-8468-1 June 24, 2026 imagemagick vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in ImageMagick. Software Description: - imagemagick: Image manipulation programs and library Details: It was discovered that ImageMagick incorrectly handled certain images when using the wavelet-denoise operator. An attacker could possibly use this issue to trigger a heap buffer over-read, resulting in information disclosure. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-27798) It was discovered that ImageMagick incorrectly handled certain DJVU images. An attacker could possibly use this issue to trigger a heap buffer over-read, resulting in information disclosure. (CVE-2026-27799) It was discovered that ImageMagick incorrectly handled certain MNG images. An attacker could possibly use this issue to trigger a stack buffer overflow, resulting in arbitrary code execution. (CVE-2026-28690) It was discovered that ImageMagick incorrectly handled certain JBIG images. An attacker could possibly use this issue to trigger a pointer dereference error, resulting in a denial of service. (CVE-2026-28691) It was discovered that ImageMagick incorrectly handled certain MAT images. An attacker could possibly use this issue to trigger a heap buffer over-read, resulting in information disclosure. (CVE-2026-28692) It was discovered that ImageMagick incorrectly handled certain DIB images. An attacker could possibly use this issue to trigger an integer overflow, resulting in arbitrary code execution. (CVE-2026-28693) Update instructions: The problem can becorrected by updating your system to the following package versions: Ubuntu 24.04 LTS imagemagick-6.q16 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro imagemagick-6.q16hdri 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libimage-magick-perl 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libimage-magick-q16-perl 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libimage-magick-q16hdri-perl 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libmagick++-6-headers 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libmagick++-6.q16-9t64 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libmagick++-6.q16-dev 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libmagick++-6.q16hdri-9t64 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libmagick++-6.q16hdri-dev 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libmagick++-dev 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libmagickcore-6-arch-config 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libmagickcore-6-headers 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libmagickcore-6.q16-7-extra 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libmagickcore-6.q16-7t64 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with UbuntuPro libmagickcore-6.q16-dev 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libmagickcore-6.q16hdri-7-extra 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libmagickcore-6.q16hdri-7t64 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libmagickcore-6.q16hdri-dev 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libmagickcore-dev 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libmagickwand-6-headers 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libmagickwand-6.q16-7t64 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libmagickwand-6.q16-dev 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libmagickwand-6.q16hdri-7t64 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libmagickwand-6.q16hdri-dev 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro libmagickwand-dev 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro perlmagick 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10 Available with Ubuntu Pro Ubuntu 22.04 LTS imagemagick-6-common 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro imagemagick-6.q16 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro imagemagick-6.q16hdri 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro imagemagick-common 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libimage-magick-perl 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libimage-magick-q16-perl 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libimage-magick-q16hdri-perl 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libmagick++-6-headers 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libmagick++-6.q16-8 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libmagick++-6.q16-dev 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libmagick++-6.q16hdri-8 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libmagick++-6.q16hdri-dev 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libmagick++-dev 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libmagickcore-6-arch-config 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libmagickcore-6-headers 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libmagickcore-6.q16-6 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libmagickcore-6.q16-6-extra 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libmagickcore-6.q16-dev 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libmagickcore-6.q16hdri-6 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libmagickcore-6.q16hdri-6-extra 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libmagickcore-6.q16hdri-dev 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libmagickcore-dev 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libmagickwand-6-headers 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libmagickwand-6.q16-6 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libmagickwand-6.q16-dev 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libmagickwand-6.q16hdri-6 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libmagickwand-6.q16hdri-dev 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro libmagickwand-dev 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro perlmagick 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11 Available with Ubuntu Pro Ubuntu 20.04 LTS imagemagick-6-common 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro imagemagick-common 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro libimage-magick-perl 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro libimage-magick-q16-perl 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro libimage-magick-q16hdri-perl 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro libmagick++-6-headers 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro libmagick++-6.q16-8 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro libmagick++-6.q16-dev 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro libmagick++-6.q16hdri-dev 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro libmagick++-dev 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro libmagickcore-6-arch-config 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro libmagickcore-6-headers 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro libmagickcore-6.q16-6-extra 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro libmagickcore-6.q16-dev 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro libmagickcore-6.q16hdri-6-extra 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro libmagickcore-6.q16hdri-dev 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro libmagickcore-dev 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro libmagickwand-6-headers 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro libmagickwand-6.q16-6 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro libmagickwand-6.q16-dev 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro libmagickwand-6.q16hdri-6 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro libmagickwand-6.q16hdri-dev 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro libmagickwand-dev 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro perlmagick 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11 Available with Ubuntu Pro Ubuntu 18.04 LTS imagemagick-6.q16 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro imagemagick-6.q16hdri 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libimage-magick-perl 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libimage-magick-q16-perl 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libimage-magick-q16hdri-perl 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libmagick++-6-headers 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libmagick++-6.q16-7 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libmagick++-6.q16-dev 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libmagick++-6.q16hdri-7 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libmagick++-6.q16hdri-dev 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libmagick++-dev 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libmagickcore-6.q16-3 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libmagickcore-6.q16-3-extra 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libmagickcore-6.q16-dev 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libmagickcore-6.q16hdri-3 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libmagickcore-6.q16hdri-3-extra 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libmagickcore-6.q16hdri-dev 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libmagickcore-dev 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libmagickwand-6-headers 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libmagickwand-6.q16-3 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libmagickwand-6.q16-dev 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libmagickwand-6.q16hdri-3 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libmagickwand-6.q16hdri-dev 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro libmagickwand-dev 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro perlmagick 8:6.9.7.4+dfsg-16ubuntu6.15+esm13 Available with Ubuntu Pro Ubuntu 16.04 LTS imagemagick 8:6.8.9.9-7ubuntu5.16+esm21 Available with Ubuntu Pro imagemagick-6.q16 8:6.8.9.9-7ubuntu5.16+esm21 Available with Ubuntu Pro imagemagick-common 8:6.8.9.9-7ubuntu5.16+esm21 Available with Ubuntu Pro libimage-magick-perl 8:6.8.9.9-7ubuntu5.16+esm21 Available with Ubuntu Pro libimage-magick-q16-perl 8:6.8.9.9-7ubuntu5.16+esm21 Available with Ubuntu Pro libmagick++-6-headers 8:6.8.9.9-7ubuntu5.16+esm21 Available with Ubuntu Pro libmagick++-6.q16-5v5 8:6.8.9.9-7ubuntu5.16+esm21 Available with Ubuntu Pro libmagick++-6.q16-dev 8:6.8.9.9-7ubuntu5.16+esm21 Available with Ubuntu Pro libmagickcore-6-arch-config 8:6.8.9.9-7ubuntu5.16+esm21 Available with Ubuntu Pro libmagickcore-6-headers 8:6.8.9.9-7ubuntu5.16+esm21 Available with Ubuntu Pro libmagickcore-6.q16-2 8:6.8.9.9-7ubuntu5.16+esm21 Available with Ubuntu Pro libmagickcore-6.q16-2-extra 8:6.8.9.9-7ubuntu5.16+esm21 Available with Ubuntu Pro libmagickcore-6.q16-dev 8:6.8.9.9-7ubuntu5.16+esm21 Available with Ubuntu Pro libmagickwand-6-headers 8:6.8.9.9-7ubuntu5.16+esm21 Available with Ubuntu Pro libmagickwand-6.q16-2 8:6.8.9.9-7ubuntu5.16+esm21 Available with Ubuntu Pro libmagickwand-6.q16-dev 8:6.8.9.9-7ubuntu5.16+esm21 Available with Ubuntu Pro perlmagick 8:6.8.9.9-7ubuntu5.16+esm21 Available with Ubuntu Pro Ubuntu 14.04 LTS imagemagick 8:6.7.7.10-6ubuntu3.13+esm22 Available with Ubuntu Pro imagemagick-common 8:6.7.7.10-6ubuntu3.13+esm22 Available with Ubuntu Pro libmagick++-dev 8:6.7.7.10-6ubuntu3.13+esm22 Available with Ubuntu Pro libmagick++5 8:6.7.7.10-6ubuntu3.13+esm22 Available with Ubuntu Pro libmagickcore-dev 8:6.7.7.10-6ubuntu3.13+esm22 Available with Ubuntu Pro libmagickcore5 8:6.7.7.10-6ubuntu3.13+esm22 Available with Ubuntu Pro libmagickcore5-extra 8:6.7.7.10-6ubuntu3.13+esm22 Available with Ubuntu Pro libmagickwand-dev 8:6.7.7.10-6ubuntu3.13+esm22 Available with Ubuntu Pro libmagickwand5 8:6.7.7.10-6ubuntu3.13+esm22 Available with Ubuntu Pro perlmagick 8:6.7.7.10-6ubuntu3.13+esm22 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8468-1 CVE-2026-27798, CVE-2026-27799, CVE-2026-28690, CVE-2026-28691, CVE-2026-28692, CVE-2026-28693 . Several security issues addressed in ImageMagick for Ubuntu releases, focusing on information disclosure and code execution risks.. ImageMagick security, Ubuntu advisory, buffer overflow, code execution threat. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 25, 2026 Important Ubuntu
219

Rocky Linux GIMP Significant Remote Code Execution Patch RLSA-2026-1574

Important: gimp:2.8 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:1574", "synopsis": "Important: gimp:2.8 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for pygtk2, module.gimp, module.python2-pycairo, gimp, module.pygobject2, pygobject2, python2-pycairo, module.pygtk2.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo.\n\nSecurity Fix(es):\n\n* gimp: GIMP: Remote Code Execution via PNM file parsing integer overflow (CVE-2025-14422)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2424766", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2424766", "description": ""}], "cves": [{"name": "CVE-2025-14422", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-14422", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-190"}], "references": [], "publishedAt": "2026-01-30T22:07:09.318241Z", "rpms": {"Rocky Linux 8": {"nvras": ["gimp-2:2.8.22-26.module+el8.10.0+40033+6fd27379.3.aarch64.rpm", "gimp-2:2.8.22-26.module+el8.10.0+1927+52edb5a0.aarch64.rpm", "gimp-2:2.8.22-26.module+el8.10.0+1998+a08ccc48.2.aarch64.rpm", "gimp-2:2.8.22-26.module+el8.10.0+1927+52edb5a0.src.rpm", "gimp-2:2.8.22-26.module+el8.10.0+40033+6fd27379.3.src.rpm", "gimp-2:2.8.22-26.module+el8.10.0+1998+a08ccc48.2.src.rpm","gimp-2:2.8.22-26.module+el8.10.0+1927+52edb5a0.x86_64.rpm", "gimp-2:2.8.22-26.module+el8.10.0+1998+a08ccc48.2.x86_64.rpm", "gimp-2:2.8.22-26.module+el8.10.0+40033+6fd27379.3.x86_64.rpm", "gimp-debuginfo-2:2.8.22-26.module+el8.10.0+40033+6fd27379.3.aarch64.rpm", "gimp-debuginfo-2:2.8.22-26.module+el8.10.0+1998+a08ccc48.2.aarch64.rpm", "gimp-debuginfo-2:2.8.22-26.module+el8.10.0+1927+52edb5a0.aarch64.rpm", "gimp-debuginfo-2:2.8.22-26.module+el8.10.0+1927+52edb5a0.x86_64.rpm", "gimp-debuginfo-2:2.8.22-26.module+el8.10.0+1998+a08ccc48.2.x86_64.rpm", "gimp-debuginfo-2:2.8.22-26.module+el8.10.0+40033+6fd27379.3.x86_64.rpm", "gimp-debugsource-2:2.8.22-26.module+el8.10.0+1927+52edb5a0.aarch64.rpm", "gimp-debugsource-2:2.8.22-26.module+el8.10.0+40033+6fd27379.3.aarch64.rpm", "gimp-debugsource-2:2.8.22-26.module+el8.10.0+1998+a08ccc48.2.aarch64.rpm", "gimp-debugsource-2:2.8.22-26.module+el8.10.0+1927+52edb5a0.x86_64.rpm", "gimp-debugsource-2:2.8.22-26.module+el8.10.0+1998+a08ccc48.2.x86_64.rpm", "gimp-debugsource-2:2.8.22-26.module+el8.10.0+40033+6fd27379.3.x86_64.rpm", "gimp-devel-2:2.8.22-26.module+el8.10.0+1927+52edb5a0.aarch64.rpm", "gimp-devel-2:2.8.22-26.module+el8.10.0+1998+a08ccc48.2.aarch64.rpm", "gimp-devel-2:2.8.22-26.module+el8.10.0+40033+6fd27379.3.aarch64.rpm", "gimp-devel-2:2.8.22-26.module+el8.10.0+40033+6fd27379.3.x86_64.rpm", "gimp-devel-2:2.8.22-26.module+el8.10.0+1927+52edb5a0.x86_64.rpm", "gimp-devel-2:2.8.22-26.module+el8.10.0+1998+a08ccc48.2.x86_64.rpm", "gimp-devel-tools-2:2.8.22-26.module+el8.10.0+1998+a08ccc48.2.aarch64.rpm", "gimp-devel-tools-2:2.8.22-26.module+el8.10.0+1927+52edb5a0.aarch64.rpm", "gimp-devel-tools-2:2.8.22-26.module+el8.10.0+40033+6fd27379.3.aarch64.rpm", "gimp-devel-tools-2:2.8.22-26.module+el8.10.0+40033+6fd27379.3.x86_64.rpm", "gimp-devel-tools-2:2.8.22-26.module+el8.10.0+1998+a08ccc48.2.x86_64.rpm", "gimp-devel-tools-2:2.8.22-26.module+el8.10.0+1927+52edb5a0.x86_64.rpm", "gimp-devel-tools-debuginfo-2:2.8.22-26.module+el8.10.0+40033+6fd27379.3.aarch64.rpm","gimp-devel-tools-debuginfo-2:2.8.22-26.module+el8.10.0+1927+52edb5a0.aarch64.rpm", "gimp-devel-tools-debuginfo-2:2.8.22-26.module+el8.10.0+1998+a08ccc48.2.aarch64.rpm", "gimp-devel-tools-debuginfo-2:2.8.22-26.module+el8.10.0+40033+6fd27379.3.x86_64.rpm", "gimp-devel-tools-debuginfo-2:2.8.22-26.module+el8.10.0+1927+52edb5a0.x86_64.rpm", "gimp-devel-tools-debuginfo-2:2.8.22-26.module+el8.10.0+1998+a08ccc48.2.x86_64.rpm", "gimp-libs-2:2.8.22-26.module+el8.10.0+1927+52edb5a0.aarch64.rpm", "gimp-libs-2:2.8.22-26.module+el8.10.0+40033+6fd27379.3.aarch64.rpm", "gimp-libs-2:2.8.22-26.module+el8.10.0+1998+a08ccc48.2.aarch64.rpm", "gimp-libs-2:2.8.22-26.module+el8.10.0+1998+a08ccc48.2.x86_64.rpm", "gimp-libs-2:2.8.22-26.module+el8.10.0+1927+52edb5a0.x86_64.rpm", "gimp-libs-2:2.8.22-26.module+el8.10.0+40033+6fd27379.3.x86_64.rpm", "gimp-libs-debuginfo-2:2.8.22-26.module+el8.10.0+1998+a08ccc48.2.aarch64.rpm", "gimp-libs-debuginfo-2:2.8.22-26.module+el8.10.0+1927+52edb5a0.aarch64.rpm", "gimp-libs-debuginfo-2:2.8.22-26.module+el8.10.0+40033+6fd27379.3.aarch64.rpm", "gimp-libs-debuginfo-2:2.8.22-26.module+el8.10.0+1927+52edb5a0.x86_64.rpm", "gimp-libs-debuginfo-2:2.8.22-26.module+el8.10.0+40033+6fd27379.3.x86_64.rpm", "gimp-libs-debuginfo-2:2.8.22-26.module+el8.10.0+1998+a08ccc48.2.x86_64.rpm", "pygobject2-0:2.28.7-5.module+el8.10.0+1927+52edb5a0.aarch64.rpm", "pygobject2-0:2.28.7-5.module+el8.10.0+1927+52edb5a0.src.rpm", "pygobject2-0:2.28.7-5.module+el8.10.0+1927+52edb5a0.x86_64.rpm", "pygobject2-codegen-0:2.28.7-5.module+el8.10.0+1927+52edb5a0.aarch64.rpm", "pygobject2-codegen-0:2.28.7-5.module+el8.10.0+1927+52edb5a0.x86_64.rpm", "pygobject2-debuginfo-0:2.28.7-5.module+el8.10.0+1927+52edb5a0.aarch64.rpm", "pygobject2-debuginfo-0:2.28.7-5.module+el8.10.0+1927+52edb5a0.x86_64.rpm", "pygobject2-debugsource-0:2.28.7-5.module+el8.10.0+1927+52edb5a0.aarch64.rpm", "pygobject2-debugsource-0:2.28.7-5.module+el8.10.0+1927+52edb5a0.x86_64.rpm", "pygobject2-devel-0:2.28.7-5.module+el8.10.0+1927+52edb5a0.aarch64.rpm","pygobject2-devel-0:2.28.7-5.module+el8.10.0+1927+52edb5a0.x86_64.rpm", "pygobject2-doc-0:2.28.7-5.module+el8.10.0+1927+52edb5a0.aarch64.rpm", "pygobject2-doc-0:2.28.7-5.module+el8.10.0+1927+52edb5a0.x86_64.rpm", "pygtk2-0:2.24.0-25.module+el8.9.0+1723+9bc93544.aarch64.rpm", "pygtk2-0:2.24.0-25.module+el8.9.0+1723+9bc93544.src.rpm", "pygtk2-0:2.24.0-25.module+el8.9.0+1723+9bc93544.x86_64.rpm", "pygtk2-codegen-0:2.24.0-25.module+el8.9.0+1723+9bc93544.aarch64.rpm", "pygtk2-codegen-0:2.24.0-25.module+el8.9.0+1723+9bc93544.x86_64.rpm", "pygtk2-debuginfo-0:2.24.0-25.module+el8.9.0+1723+9bc93544.aarch64.rpm", "pygtk2-debuginfo-0:2.24.0-25.module+el8.9.0+1723+9bc93544.x86_64.rpm", "pygtk2-debugsource-0:2.24.0-25.module+el8.9.0+1723+9bc93544.aarch64.rpm", "pygtk2-debugsource-0:2.24.0-25.module+el8.9.0+1723+9bc93544.x86_64.rpm", "pygtk2-devel-0:2.24.0-25.module+el8.9.0+1723+9bc93544.aarch64.rpm", "pygtk2-devel-0:2.24.0-25.module+el8.9.0+1723+9bc93544.x86_64.rpm", "pygtk2-doc-0:2.24.0-25.module+el8.9.0+1723+9bc93544.noarch.rpm", "python2-cairo-0:1.16.3-7.module+el8.10.0+1927+52edb5a0.aarch64.rpm", "python2-cairo-0:1.16.3-7.module+el8.10.0+1927+52edb5a0.x86_64.rpm", "python2-cairo-debuginfo-0:1.16.3-7.module+el8.10.0+1927+52edb5a0.aarch64.rpm", "python2-cairo-debuginfo-0:1.16.3-7.module+el8.10.0+1927+52edb5a0.x86_64.rpm", "python2-cairo-devel-0:1.16.3-7.module+el8.10.0+1927+52edb5a0.aarch64.rpm", "python2-cairo-devel-0:1.16.3-7.module+el8.10.0+1927+52edb5a0.x86_64.rpm", "python2-pycairo-0:1.16.3-7.module+el8.10.0+1927+52edb5a0.src.rpm", "python2-pycairo-debugsource-0:1.16.3-7.module+el8.10.0+1927+52edb5a0.aarch64.rpm", "python2-pycairo-debugsource-0:1.16.3-7.module+el8.10.0+1927+52edb5a0.x86_64.rpm", "gimp-2:2.8.22-26.module+el8.10.0+40075+a21479b4.4.aarch64.rpm", "gimp-2:2.8.22-26.module+el8.10.0+40075+a21479b4.4.src.rpm", "gimp-2:2.8.22-26.module+el8.10.0+40075+a21479b4.4.x86_64.rpm", "gimp-debuginfo-2:2.8.22-26.module+el8.10.0+40075+a21479b4.4.aarch64.rpm","gimp-debuginfo-2:2.8.22-26.module+el8.10.0+40075+a21479b4.4.x86_64.rpm", "gimp-debugsource-2:2.8.22-26.module+el8.10.0+40075+a21479b4.4.aarch64.rpm", "gimp-debugsource-2:2.8.22-26.module+el8.10.0+40075+a21479b4.4.x86_64.rpm", "gimp-devel-2:2.8.22-26.module+el8.10.0+40075+a21479b4.4.aarch64.rpm", "gimp-devel-2:2.8.22-26.module+el8.10.0+40075+a21479b4.4.x86_64.rpm", "gimp-devel-tools-2:2.8.22-26.module+el8.10.0+40075+a21479b4.4.aarch64.rpm", "gimp-devel-tools-2:2.8.22-26.module+el8.10.0+40075+a21479b4.4.x86_64.rpm", "gimp-devel-tools-debuginfo-2:2.8.22-26.module+el8.10.0+40075+a21479b4.4.aarch64.rpm", "gimp-devel-tools-debuginfo-2:2.8.22-26.module+el8.10.0+40075+a21479b4.4.x86_64.rpm", "gimp-libs-2:2.8.22-26.module+el8.10.0+40075+a21479b4.4.aarch64.rpm", "gimp-libs-2:2.8.22-26.module+el8.10.0+40075+a21479b4.4.x86_64.rpm", "gimp-libs-debuginfo-2:2.8.22-26.module+el8.10.0+40075+a21479b4.4.aarch64.rpm", "gimp-libs-debuginfo-2:2.8.22-26.module+el8.10.0+40075+a21479b4.4.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. GIMP receives an important security update addressing remote code execution risk on Rocky Linux, enhancing overall protection.. GIMP Update, Rocky Linux Security, Remote Code Execution, Image Editing Vulnerability, Linux Security Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 30, 2026 Important Rocky Linux
217

Oracle Linux 7: ImageMagick Important Update ELSA-2025-16313 CVE-2025-57803

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-16313 http://linux.oracle.com/errata/ELSA-2025-16313.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: ImageMagick-6.9.10.68-7.0.3.el7_9.i686.rpm ImageMagick-6.9.10.68-7.0.3.el7_9.x86_64.rpm ImageMagick-c++-6.9.10.68-7.0.3.el7_9.i686.rpm ImageMagick-c++-6.9.10.68-7.0.3.el7_9.x86_64.rpm ImageMagick-c++-devel-6.9.10.68-7.0.3.el7_9.i686.rpm ImageMagick-c++-devel-6.9.10.68-7.0.3.el7_9.x86_64.rpm ImageMagick-devel-6.9.10.68-7.0.3.el7_9.i686.rpm ImageMagick-devel-6.9.10.68-7.0.3.el7_9.x86_64.rpm ImageMagick-doc-6.9.10.68-7.0.3.el7_9.x86_64.rpm ImageMagick-perl-6.9.10.68-7.0.3.el7_9.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates/ImageMagick-6.9.10.68-7.0.3.el7_9.src.rpm Related CVEs: CVE-2025-57803 Description of changes: [6.9.10.68-7.0.3] - Security update CVE-2025-57803 [Orabug: 38455460] [6.9.10.68-7.0.1] - Fix for CVE-2025-55154 [Orabug: 38417011] _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Security update for ImageMagick on Oracle Linux 7 addressing CVE-2025-57803 is crucial for system integrity.. ImageMagick security patch, Oracle Linux 7 update, ImageMagick vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 16, 2025 Important Oracle
89

Fedora 41: FEDORA-2025-e2287efebb critical: ImageMagick buffer issues

Automatic update for ImageMagick-7.1.1.47-1.fc41. Changelog for ImageMagick * Sun Mar 30 2025 Packit - 1:7.1.1.47-1 - Update to version 7.1.1.47 - Resolves: rhbz#2356054. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-e2287efebb 2025-04-25 01:47:40.996703+00:00 -------------------------------------------------------------------------------- Name : ImageMagick Product : Fedora 41 Version : 7.1.1.47 Release : 1.fc41 URL : https://imagemagick.org/ Summary : An X application for displaying and manipulating images Description : ImageMagick is an image display and manipulation tool for the X Window System. ImageMagick can read and write JPEG, TIFF, PNM, GIF, and Photo CD image formats. It can resize, rotate, sharpen, color reduce, or add special effects to an image, and when finished you can either save the completed work in the original format or a different one. ImageMagick also includes command line programs for creating animated or transparent .gifs, creating composite images, creating thumbnail images, and more. ImageMagick is one of your choices if you need a program to manipulate and display images. If you want to develop your own applications which use ImageMagick code or APIs, you need to install ImageMagick-devel as well. -------------------------------------------------------------------------------- Update Information: Automatic update for ImageMagick-7.1.1.47-1.fc41. Changelog for ImageMagick * Sun Mar 30 2025 Packit - 1:7.1.1.47-1 - Update to version 7.1.1.47 - Resolves: rhbz#2356054 -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 30 2025 Packit - 1:7.1.1.47-1 - Update to version 7.1.1.47 - Resolves: rhbz#2356054 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2356054 - ImageMagick-7.1.1.47 is available https://bugzilla.redhat.com/show_bug.cgi?id=2356054 [ 2 ] Bug #2361983 - CVE-2025-46393 ImageMagick: Incorrect Calculation of Buffer Size in ImageMagick's Multispectral MIFF Processing [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2361983 [ 3 ] Bug #2361986 - CVE-2025-43965 ImageMagick: Incorrect Handling of Image Depth in MIFF Processing in ImageMagick [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2361986 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e2287efebb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . The latest ImageMagick update for Fedora 41 addresses significant buffer vulnerabilities, ensuring improved security and performance enhancements.. ImageMagick update, Fedora security, buffer overflow, image processing software. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 25, 2025 Critical Fedora
89

Fedora 38: 2023-90ed807e04 Critical Libpano13 Update Notification

Upstream release. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-90ed807e04 2023-09-20 01:30:28.946871 -------------------------------------------------------------------------------- Name : libpano13 Product : Fedora 38 Version : 2.9.22 Release : 1.fc38 URL : Summary : Library for manipulating panoramic images Description : Helmut Dersch's Panorama Tools library. Provides very high quality manipulation, correction and stitching of panoramic photographs. -------------------------------------------------------------------------------- Update Information: Upstream release -------------------------------------------------------------------------------- ChangeLog: * Mon Sep 11 2023 Bruno Postle - 2.9.22-1 - Upstream release * Thu Jul 20 2023 Fedora Release Engineering - 2.9.21-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-90ed807e04' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives:https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Discover the latest libpano13 update for Fedora 38, featuring enhanced stitching, broader format support, and improved performance for better usability. libpano13 Fedora update image processing panoramic. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 20, 2023 Critical Fedora
89

Fedora 37 Advisory FEDORA-2023-f5a6136ac8: libpano13 Upstream Release

Upstream release. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-f5a6136ac8 2023-09-20 01:05:47.011057 -------------------------------------------------------------------------------- Name : libpano13 Product : Fedora 37 Version : 2.9.22 Release : 1.fc37 URL : Summary : Library for manipulating panoramic images Description : Helmut Dersch's Panorama Tools library. Provides very high quality manipulation, correction and stitching of panoramic photographs. -------------------------------------------------------------------------------- Update Information: Upstream release -------------------------------------------------------------------------------- ChangeLog: * Mon Sep 11 2023 Bruno Postle - 2.9.22-1 - Upstream release * Thu Jul 20 2023 Fedora Release Engineering - 2.9.21-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Thu Jan 19 2023 Fedora Release Engineering - 2.9.21-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Tue Jan 17 2023 Florian Weimer - 2.9.21-4 - C99 compatibility fix -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-f5a6136ac8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Optimize wide-angle photographs seamlessly using the new libpano14 release for Fedora 38, improving functionality and addressing bugs.. Libpano13, Fedora Updates, Panoramic Image Tools. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Sep 20, 2023 Informational Fedora
197

Debian LTS: DLA-3429-1 Severe: Imagemagick Buffer Overflow DoS

Multiple vulnerabilities were fixed in imagemagick, a software suite, used for editing and manipulating digital images. CVE-2021-20176 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3429-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Bastien Roucaries May 21, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : imagemagick Version : 8:6.9.10.23+dfsg-2.1+deb10u5 CVE ID : CVE-2021-20176 CVE-2021-20241 CVE-2021-20243 CVE-2021-20244 CVE-2021-20245 CVE-2021-20246 CVE-2021-20309 CVE-2021-20312 CVE-2021-20313 CVE-2021-39212 CVE-2022-28463 CVE-2022-32545 CVE-2022-32546 CVE-2022-32547 Debian Bug : 996588 1013282 1016442 Multiple vulnerabilities were fixed in imagemagick, a software suite, used for editing and manipulating digital images. CVE-2021-20176 A divide by zero was found in gem.c file. CVE-2021-20241 A divide by zero was found in jp2 coder. CVE-2021-20243 A divide by zero was found in dcm coder. CVE-2021-20244 A divide by zero was found in fx.c. CVE-2021-20245 A divide by zero was found in webp coder. CVE-2021-20246 A divide by zero was found in resample.c. CVE-2021-20309 A divide by zero was found in WaveImage.c CVE-2021-20312 An integer overflow was found in WriteTHUMBNAILImage() of coders/thumbnail.c CVE-2021-20313 A potential cipher leak was found when the calculate signatures in TransformSignature(). CVE-2021-39212 A policy bypass was found for postscript files. CVE-2022-28463 A bufer overflow was found in buffer overflow in cin coder. CVE-2022-32545 A undefined behavior (conversion outside the range of representable values of type 'unsigned char') was found in psd file handling. CVE-2022-32546 A undefined behavior (conversionoutside the range of representable values of type 'long') was found in pcl file handling. CVE-2022-32547 An unaligned access was found in property.c For Debian 10 buster, these problems have been fixed in version 8:6.9.10.23+dfsg-2.1+deb10u5. We recommend that you upgrade your imagemagick packages. For the detailed security status of imagemagick please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/imagemagick Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-3429-1 highlights vulnerabilities in imagemagick, enhancing the security framework for image manipulation software.. imagemagick security update, Debian LTS vulnerabilities, image manipulation flaws, DoS in imagemagick. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 21, 2023 Critical Debian LTS
203

Mageia 8: MGASA-2022-0446 Moderate: ImageMagick DoS And Memory Leak

A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects memory leaks. (CVE-2021-3574) A flaw was found in ImageMagick. The vulnerability occurs due to improper . MGASA-2022-0446 - Updated imagemagick packages fix security vulnerability Publication date: 06 Dec 2022 URL: https://advisories.mageia.org/MGASA-2022-0446.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-3574, CVE-2021-4219, CVE-2021-20224, CVE-2021-20309, CVE-2021-20311, CVE-2021-20312, CVE-2021-20313, CVE-2022-0284, CVE-2022-1114, CVE-2022-1270, CVE-2022-2719, CVE-2022-3213, CVE-2022-28463, CVE-2022-32545, CVE-2022-32546, CVE-2022-32547 A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects memory leaks. (CVE-2021-3574) A flaw was found in ImageMagick. The vulnerability occurs due to improper use of open functions and leads to a denial of service. This flaw allows an attacker to crash the system. (CVE-2021-4219) An integer overflow issue was discovered in ImageMagick's ExportIndexQuantum() function in MagickCore/quantum-export.c. Function calls to GetPixelIndex() could result in values outside the range of representable for the 'unsigned char'. When ImageMagick processes a crafted pdf file, this could lead to an undefined behaviour or a crash. (CVE-2021-20224) A flaw was found in ImageMagick in versions before 7.0.11 and before 6.9.12, where a division by zero in WaveImage() of MagickCore/visual-effects.c may trigger undefined behavior via a crafted image file submitted to an application using ImageMagick. The highest threat from this vulnerability is to system availability. (CVE-2021-20309) A flaw was found in ImageMagick in versions before 7.0.11, where a division by zero in sRGBTransformImage() in the MagickCore/colorspace.c may trigger undefined behavior via a crafted image file that is submitted by an attacker processed byan application using ImageMagick. The highest threat from this vulnerability is to system availability. (CVE-2021-20311) A flaw was found in ImageMagick in versions 7.0.11, where an integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c may trigger undefined behavior via a crafted image file that is submitted by an attacker and processed by an application using ImageMagick. The highest threat from this vulnerability is to system availability. (CVE-2021-20312) A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. The highest threat from this vulnerability is to data confidentiality. (CVE-2021-20313) A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulnerability is triggered when an attacker passes a specially crafted Tagged Image File Format (TIFF) image to convert it into a PICON file format. This issue can potentially lead to a denial of service and information disclosure. (CVE-2022-0284) A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion, potentially leading to information disclosure and a denial of service. (CVE-2022-1114) In GraphicsMagick, a heap buffer overflow was found when parsing MIFF. (CVE-2022-1270) In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image list. This could potentially cause a denial of service. This was fixed in upstream ImageMagick version 7.1.0-30. (CVE-2022-2719) A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service. (CVE-2022-3213) ImageMagick 7.1.0-27 is vulnerable to Buffer Overflow. (CVE-2022-28463) A vulnerability wasfound in ImageMagick, causing an outside the range of representable values of type 'unsigned char' at coders/psd.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior. (CVE-2022-32545) A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior. (CVE-2022-32546) In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignment and for type 'float', which requires 4 byte alignment at MagickCore/property.c. Whenever crafted or untrusted input is processed by ImageMagick, this causes a negative impact to application availability or other problems related to undefined behavior. (CVE-2022-32547) References: - https://bugs.mageia.org/show_bug.cgi?id=29054 - - https://ubuntu.com/security/notices/USN-5158-1 - - https://lists.debian.org/debian-lts-announce/2022/05/msg00018.html - - https://lists.suse.com/pipermail/sle-security-updates/2022-May/011200.html - https://ubuntu.com/security/notices/USN-5456-1 - - https://ubuntu.com/security/notices/USN-5534-1 - https://lists.suse.com/pipermail/sle-security-updates/2022-September/012065.html - - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/LNVDNM4ZEIYPT3SLZHPYN7OG4CZLEXZJ/ - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/T6VPXZJUL64MXAMQ4JA6V6TYNOXDC6SQ/ - - https://ubuntu.com/security/notices/USN-5736-1 - https://www.cve.org/CVERecord?id=CVE-2021-3574 - https://www.cve.org/CVERecord?id=CVE-2021-4219 - https://www.cve.org/CVERecord?id=CVE-2021-20224 - https://www.cve.org/CVERecord?id=CVE-2021-20309 - https://www.cve.org/CVERecord?id=CVE-2021-20311 - https://www.cve.org/CVERecord?id=CVE-2021-20312 -https://www.cve.org/CVERecord?id=CVE-2021-20313 - https://www.cve.org/CVERecord?id=CVE-2022-0284 - https://www.cve.org/CVERecord?id=CVE-2022-1114 - https://www.cve.org/CVERecord?id=CVE-2022-1270 - https://www.cve.org/CVERecord?id=CVE-2022-2719 - https://www.cve.org/CVERecord?id=CVE-2022-3213 - https://www.cve.org/CVERecord?id=CVE-2022-28463 - https://www.cve.org/CVERecord?id=CVE-2022-32545 - https://www.cve.org/CVERecord?id=CVE-2022-32546 - https://www.cve.org/CVERecord?id=CVE-2022-32547 SRPMS: - 8/tainted/imagemagick-7.1.0.52-1.1.mga8.tainted - 8/tainted/abydos-0.2.3-4.2.mga8.tainted - 8/tainted/transcode-1.1.7-29.2.mga8.tainted - 8/tainted/xine-lib1.2-1.2.11-1.2.mga8.tainted - 8/core/imagemagick-7.1.0.52-1.1.mga8 - 8/core/abydos-0.2.3-4.2.mga8 - 8/core/converseen-0.9.8.1-4.2.mga8 - 8/core/digikam-7.1.0-4.2.mga8 - 8/core/libopenshot-0.2.5-5.2.mga8 - 8/core/php-imagick-3.4.5-0.git20201230.2.2.mga8 - 8/core/synfig-1.2.2-11.2.mga8 - 8/core/windowmaker-0.95.9-3.2.mga8 - 8/core/xine-lib1.2-1.2.11-1.2.mga8 - 8/core/zbar-0.23.1-5.2.mga8 . Recent updates to ImageMagick packages fix various security flaws; discover methods to protect your Mageia system today.. mageia security update, imagemagick exploit, system safety. . LinuxSecurity.com Team

Calendar%202 Dec 07, 2022 Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200