• [SECURITY] [DSA 4715-1] imagemagick security update

    From Moritz Muehlenhoff@1:229/2 to All on Thu Jul 2 20:40:01 2020
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4715-1 [email protected] https://www.debian.org/security/ Moritz Muehlenhoff
    July 02, 2020 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : imagemagick
    CVE ID : CVE-2019-13300 CVE-2019-13304 CVE-2019-13306 CVE-2019-13307
    CVE-2019-15140 CVE-2019-19948

    This update fixes multiple vulnerabilities in Imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising
    may result in denial of service, memory disclosure or potentially the
    execution of arbitrary code if malformed image files are processed.

    For the oldstable distribution (stretch), these problems have been fixed
    in version 8:6.9.7.4+dfsg-11+deb9u8.

    We recommend that you upgrade your imagemagick packages.

    For the detailed security status of imagemagick please refer to
    its security tracker page at: https://security-tracker.debian.org/tracker/imagemagick

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl7+KI0ACgkQEMKTtsN8 TjYf6BAAuE+XSVJzQMenV4PJvbbDAoMP1p23VpHP9W2i7yxf1zF+KC9ouNWlQDue eX8cg2NqbN2mnvk7deCK3Ngxlx+oMYXl9eiCF2cjbdXeFoK8E4F/15slSn1bMb6z C6hrrpqE1Omx0kefUhBSSQ2C+RLowvPJjpTqlnYe10GygRUMMpRVS+aO5HjLZQVb 8cLvlLiWUCRKU0nsosLh3cvFz/OsW7PJ+uU7SJJQkfrwJiKi00JjDW+LFYlag/CH VAt4opWfN1gZW/sBxGbA77qB+r1MFyfBU3d9yi4mWRl7HyS34LFL87Xl8lKkj5sN /g4afp92UQHB4G82JvFgqJcup+zvHUK8KNcQN76fowchaugoTxg8xZsuJB5zun1j YKfFc1JJwwa3PBjFktz0iRJYE2PpvfccX2TdtyLPMSqIvfN3oifG2Wl/rsI6hLkn vAnaGuDuFY6HqVytNmQ5vZ0nOEPMz2OX0H1fGZzcIQrL1fO0wmPldLZulGiPbVr4 s4o1o/UlL8fgepA4eGFwzQmhie3ZR9PtNPMcfKLDv1ZS7kZA6Q3pwj89fWKmV8Cc GrdtByzLz//cBxhPNbdXYNr4KXEMCd1+fIY+etIEJ5z+PsFCJkG2nSbScjSdBJpq 3pDqW5w2mphOszZo5U3pe49r0wq0spoiTWOOqulgk9k0iWSU57w=
    =fL5E
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)