DSA-4712-1 imagemagick -- security update

Related Vulnerabilities: CVE-2019-7175   CVE-2019-7395   CVE-2019-7396   CVE-2019-7397   CVE-2019-7398   CVE-2019-10649   CVE-2019-11470   CVE-2019-11472   CVE-2019-11597   CVE-2019-11598   CVE-2019-12974   CVE-2019-12975   CVE-2019-12976   CVE-2019-12977   CVE-2019-12978   CVE-2019-12979   CVE-2019-13135   CVE-2019-13137   CVE-2019-13295   CVE-2019-13297   CVE-2019-13300   CVE-2019-13301   CVE-2019-13304   CVE-2019-13305   CVE-2019-13307   CVE-2019-13308   CVE-2019-13309   CVE-2019-13311   CVE-2019-13454   CVE-2019-14981   CVE-2019-15139   CVE-2019-15140   CVE-2019-16708   CVE-2019-16710   CVE-2019-16711   CVE-2019-16713   CVE-2019-19948   CVE-2019-19949  

This update fixes multiple vulnerabilities in Imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or potentially the execution of arbitrary code if malformed image files are processed. For the stable distribution (buster), these problems have been fixed in version 8:6.9.10.23+dfsg-2.1+deb10u1. We recommend that you upgrade your imagemagick packages. For the detailed security status of imagemagick please refer to its security tracker page at: https://security-tracker.debian.org/tracker/imagemagick

Debian Security Advisory

DSA-4712-1 imagemagick -- security update

Date Reported:
30 Jun 2020
Affected Packages:
imagemagick
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2019-7175, CVE-2019-7395, CVE-2019-7396, CVE-2019-7397, CVE-2019-7398, CVE-2019-10649, CVE-2019-11470, CVE-2019-11472, CVE-2019-11597, CVE-2019-11598, CVE-2019-12974, CVE-2019-12975, CVE-2019-12976, CVE-2019-12977, CVE-2019-12978, CVE-2019-12979, CVE-2019-13135, CVE-2019-13137, CVE-2019-13295, CVE-2019-13297, CVE-2019-13300, CVE-2019-13301, CVE-2019-13304, CVE-2019-13305, CVE-2019-13307, CVE-2019-13308, CVE-2019-13309, CVE-2019-13311, CVE-2019-13454, CVE-2019-14981, CVE-2019-15139, CVE-2019-15140, CVE-2019-16708, CVE-2019-16710, CVE-2019-16711, CVE-2019-16713, CVE-2019-19948, CVE-2019-19949.
More information:

This update fixes multiple vulnerabilities in Imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or potentially the execution of arbitrary code if malformed image files are processed.

For the stable distribution (buster), these problems have been fixed in version 8:6.9.10.23+dfsg-2.1+deb10u1.

We recommend that you upgrade your imagemagick packages.

For the detailed security status of imagemagick please refer to its security tracker page at: https://security-tracker.debian.org/tracker/imagemagick