imagemagick 8:6.9.10.14+dfsg-1 source package in Debian

Changelog

imagemagick (8:6.9.10.14+dfsg-1) unstable; urgency=medium

  * New upstream version
  * Fix new privacy breach
  * Fix duplicate files in documentation
  * Fix security bugs:
    + CVE-2018-18544: Fix a memory leak in the function WriteMSLImage of
      coders/msl.c
    + CVE-2018-18024: Fix an infinite loop in the ReadBMPImage function of the
      coders/bmp.c file can cause a DOS via a crafted bmp file.
    + CVE-2018-18023: A heap-based buffer over-read in the SVGStripString
      function of coders/svg.c, which allows attackers to cause a denial
      of service via a crafted SVG image file.
    + CVE-2018-16645: Fix an excessive memory allocation issue in the functions
      ReadBMPImage of coders/bmp.c and ReadDIBImage of coders/dib.c,
      which allows remote attackers to cause a denial of service via
      a crafted image file.
      (Closes: #910889)
    + CVE-2018-16644: Fix a missing check for length in the functions
      ReadDCMImage of coders/dcm.c and ReadPICTImage of coders/pict.c,
      which allows remote attackers to cause a denial of service via
      a crafted image.
      (Closes: #910888)
    + CVE-2018-16413: Fix a heap-based buffer over-read in the
      MagickCore/quantum-private.h PushShortPixel function when called
      from the coders/psd.c ParseImageResourceBlocks function.
      (Closes: #910887)
    + CVE-2018-16323: Fix an information disclosure vulnerability that existed
      in ImageMagick when processing XBM images. An attacker could use this
      to expose sensitive information.
      (Closes: #907776)
    + CVE-2018-16412: Fix a heap-based buffer over-read in the coders/psd.c
      ParseImageResourceBlocks function.
    + CVE-2018-17965: Fix a memory leak vulnerability in WriteSGIImage
      in coders/sgi.c.
    + CVE-2018-17966: Fix a memory leak vulnerability in WritePDBImage
      in coders/pdb.c.
    + CVE-2018-17967: Fix a memory leak vulnerability in ReadBGRImage
      in coders/bgr.c.
    + CVE-2018-18016: Fix a memory leak vulnerability in WritePCXImage
      in coders/pcx.c.

 -- Bastien Roucariès <email address hidden>  Mon, 29 Oct 2018 13:13:38 +0100

Upload details

Uploaded by:
ImageMagick Packaging Team
Uploaded to:
Sid
Original maintainer:
ImageMagick Packaging Team
Architectures:
any all
Section:
graphics
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Downloads

File Size SHA-256 Checksum
imagemagick_6.9.10.14+dfsg-1.dsc 5.0 KiB 067d2fe88c0a45752ddd4c10abbf8cc378f290e1c72d53c8582896fd36f0f31c
imagemagick_6.9.10.14+dfsg.orig.tar.xz 8.6 MiB 20f48004c696eee645c5e468b1ff291ceed2759d9c0ed75eb9e616067cc096fd
imagemagick_6.9.10.14+dfsg-1.debian.tar.xz 215.5 KiB 9f529960fdca255aa70d120320a1d9db7688c5e3c658b193384b06c2265af97c

No changes file available.

Binary packages built by this source