• [SECURITY] [DSA 4040-1] imagemagick security update

    From Moritz Muehlenhoff@1:229/2 to All on Sat Nov 18 00:00:02 2017
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4040-1 [email protected] https://www.debian.org/security/ Moritz Muehlenhoff November 17, 2017 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : imagemagick
    CVE ID : CVE-2017-11352 CVE-2017-11640 CVE-2017-12431
    CVE-2017-12640 CVE-2017-12877 CVE-2017-12983
    CVE-2017-13134 CVE-2017-13139 CVE-2017-13144
    CVE-2017-13758 CVE-2017-13769 CVE-2017-14224
    CVE-2017-14607 CVE-2017-14682 CVE-2017-14989
    CVE-2017-15277 CVE-2017-16546

    This update fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising
    may result in denial of service, memory disclosure or the execution of arbitrary code if malformed image files are processed.

    For the oldstable distribution (jessie), these problems have been fixed
    in version 8:6.8.9.9-5+deb8u11.

    We recommend that you upgrade your imagemagick packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAloPZ4oACgkQEMKTtsN8 Tjbe1hAAr4NXEDlq+oN9B5Hv1x5881qCH3P3uJQhovM3KYVotmzSXb+NOkI6iSMQ cY62ipQPi7xcOskcPWGumomMXw5Gi3kvl7YTgApP6JkJ7e06Un3CsCcP6KTGjkCw dMTuPC+eeAvmMpcjVoUy8GD33qTFiWFhQjh10gf/jFx+nLsgoMDQyrzAYvxcAQPk NOCZoUWwWH6c8P70XSCmNvDP0cN9tVL6pSK3UocaKA9Lt3H503mHPhEvy/Omd+Hp ctGHESUAi9S0Sxu2Ke1x0F1WeDq+U4KxBAGcNneqPaObuNLyHB7S2AMLdOrFIOK+ KKmMBKsVfLykxSiOHvZOFMD8burN2ORZHV/0FY7S915Y+QDvzy+Ue7b0P2HLKKRQ B7rFAXTzBQI++FYymYCkTDVd49zGaKIafi83LOnYdOy72+W5Yrfbi0ZueEQL7/Iw 9ACgmQwHL5QQwbTj/4Va79ivbbgJpLpaKWagOej2o11sPl1ZI7rDklwuGM/60EPZ pAEIyi+IJfcE186krwY29Ipszn/Gjq76gGEfnxHylgeUW83BfOIhG2mEVswv64Rb Y/6boX9UxIOYyXalVe0dAbiRcXwNA/78e/Z66CnqkoaWkDyAKtw4ZmPO7cs5w1i3 Ph05eio4SotBDwuTqA4U8Nw/1ExRAzTTwm3ErRYlHxQdAg20sJQ=
    =h86S
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)