CVE-2012-0259 / CVE-2012-0260 / CVE-2012-1798 / CVE-2012-1610

Related Vulnerabilities: CVE-2012-0259   CVE-2012-0260   CVE-2012-1798   CVE-2012-1610   CVE-2012-1185   CVE-2012-1186  

Debian Bug report logs - #667635
CVE-2012-0259 / CVE-2012-0260 / CVE-2012-1798 / CVE-2012-1610

version graph

Reported by: Moritz Muehlenhoff <muehlenhoff@univention.de>

Date: Thu, 5 Apr 2012 13:57:02 UTC

Severity: grave

Tags: security

Found in versions imagemagick/8:6.7.4.0-3, imagemagick/8:6.6.9.7-7

Fixed in versions imagemagick/8:6.7.4.0-4, imagemagick/8:6.6.0.4-3+squeeze2

Done: Vincent Fourmond <fourmond@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>:
Bug#667635; Package imagemagick. (Thu, 05 Apr 2012 13:57:05 GMT) (full text, mbox, link).


Acknowledgement sent to Moritz Muehlenhoff <muehlenhoff@univention.de>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>. (Thu, 05 Apr 2012 13:57:05 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Moritz Muehlenhoff <muehlenhoff@univention.de>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2012-0259 / CVE-2012-0260 / CVE-2012-1798 / CVE-2012-1610
Date: Thu, 05 Apr 2012 15:52:54 +0200
Package: imagemagick
Severity: grave
Tags: security

New Imagemagick issues have been discovered:
http://www.cert.fi/en/reports/2012/vulnerability635606.html

Not that the upstream fix for CVE-2012-0259 was incomplete. For the incomplete
patch, CVE-2012-1610 has been assigned.

Red Hat Bugzilla contains a more detailed writeup:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-0259
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-0260
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-1798

Cheers,
        Moritz




Information forwarded to debian-bugs-dist@lists.debian.org, ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>:
Bug#667635; Package imagemagick. (Wed, 11 Apr 2012 20:21:04 GMT) (full text, mbox, link).


Acknowledgement sent to Vincent Fourmond <fourmond@debian.org>:
Extra info received and forwarded to list. Copy sent to ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>. (Wed, 11 Apr 2012 20:21:04 GMT) (full text, mbox, link).


Message #10 received at 667635@bugs.debian.org (full text, mbox, reply):

From: Vincent Fourmond <fourmond@debian.org>
To: release@lists.debian.org
Cc: 667635@bugs.debian.org, 652650@bugs.debian.org, Bastien ROUCARIES <roucaries.bastien@gmail.com>
Subject: Advice requested for a security upload of imagemagick to unstable
Date: Wed, 11 Apr 2012 22:19:13 +0200
  Dear release team,

  We have prepared an upload of imagemagick that fixes
recently-uncovered security-related problems (#667635). I'm unsure
about what to do currently with the imagemagick ongoing transition
(#652650). Shall I upload right now with urgency=high, knowing that
anyway, it will have to wait for the transition to be over to move to
testing, or shall I wait until the transition is over to upload ? Will
is disrupt anything if I upload right now ? (the modifications are not
invasive).

  Many thanks,

      Vincent




Information forwarded to debian-bugs-dist@lists.debian.org, ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>:
Bug#667635; Package imagemagick. (Wed, 11 Apr 2012 21:18:51 GMT) (full text, mbox, link).


Acknowledgement sent to Julien Cristau <jcristau@debian.org>:
Extra info received and forwarded to list. Copy sent to ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>. (Wed, 11 Apr 2012 21:18:52 GMT) (full text, mbox, link).


Message #15 received at 667635@bugs.debian.org (full text, mbox, reply):

From: Julien Cristau <jcristau@debian.org>
To: Vincent Fourmond <fourmond@debian.org>, 652650@bugs.debian.org
Cc: 667635@bugs.debian.org, Bastien ROUCARIES <roucaries.bastien@gmail.com>
Subject: Re: Bug#652650: Advice requested for a security upload of imagemagick to unstable
Date: Wed, 11 Apr 2012 23:15:34 +0200
On Wed, Apr 11, 2012 at 22:19:13 +0200, Vincent Fourmond wrote:

>   Dear release team,
> 
>   We have prepared an upload of imagemagick that fixes
> recently-uncovered security-related problems (#667635). I'm unsure
> about what to do currently with the imagemagick ongoing transition
> (#652650). Shall I upload right now with urgency=high, knowing that
> anyway, it will have to wait for the transition to be over to move to
> testing, or shall I wait until the transition is over to upload ? Will
> is disrupt anything if I upload right now ? (the modifications are not
> invasive).
> 
No need to wait.

Cheers,
Julien




Reply sent to Bastien Roucariès <roucaries.bastien+debian@gmail.com>:
You have taken responsibility. (Wed, 11 Apr 2012 22:03:13 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <muehlenhoff@univention.de>:
Bug acknowledged by developer. (Wed, 11 Apr 2012 22:03:13 GMT) (full text, mbox, link).


Message #20 received at 667635-close@bugs.debian.org (full text, mbox, reply):

From: Bastien Roucariès <roucaries.bastien+debian@gmail.com>
To: 667635-close@bugs.debian.org
Subject: Bug#667635: fixed in imagemagick 8:6.7.4.0-4
Date: Wed, 11 Apr 2012 22:00:37 +0000
Source: imagemagick
Source-Version: 8:6.7.4.0-4

We believe that the bug you reported is fixed in the latest version of
imagemagick, which is due to be installed in the Debian FTP archive:

imagemagick-common_6.7.4.0-4_all.deb
  to main/i/imagemagick/imagemagick-common_6.7.4.0-4_all.deb
imagemagick-dbg_6.7.4.0-4_amd64.deb
  to main/i/imagemagick/imagemagick-dbg_6.7.4.0-4_amd64.deb
imagemagick-doc_6.7.4.0-4_all.deb
  to main/i/imagemagick/imagemagick-doc_6.7.4.0-4_all.deb
imagemagick_6.7.4.0-4.debian.tar.bz2
  to main/i/imagemagick/imagemagick_6.7.4.0-4.debian.tar.bz2
imagemagick_6.7.4.0-4.dsc
  to main/i/imagemagick/imagemagick_6.7.4.0-4.dsc
imagemagick_6.7.4.0-4_amd64.deb
  to main/i/imagemagick/imagemagick_6.7.4.0-4_amd64.deb
libmagick++-dev_6.7.4.0-4_amd64.deb
  to main/i/imagemagick/libmagick++-dev_6.7.4.0-4_amd64.deb
libmagick++5_6.7.4.0-4_amd64.deb
  to main/i/imagemagick/libmagick++5_6.7.4.0-4_amd64.deb
libmagickcore-dev_6.7.4.0-4_amd64.deb
  to main/i/imagemagick/libmagickcore-dev_6.7.4.0-4_amd64.deb
libmagickcore5-extra_6.7.4.0-4_amd64.deb
  to main/i/imagemagick/libmagickcore5-extra_6.7.4.0-4_amd64.deb
libmagickcore5_6.7.4.0-4_amd64.deb
  to main/i/imagemagick/libmagickcore5_6.7.4.0-4_amd64.deb
libmagickwand-dev_6.7.4.0-4_amd64.deb
  to main/i/imagemagick/libmagickwand-dev_6.7.4.0-4_amd64.deb
libmagickwand5_6.7.4.0-4_amd64.deb
  to main/i/imagemagick/libmagickwand5_6.7.4.0-4_amd64.deb
perlmagick_6.7.4.0-4_amd64.deb
  to main/i/imagemagick/perlmagick_6.7.4.0-4_amd64.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 667635@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Bastien Roucariès <roucaries.bastien+debian@gmail.com> (supplier of updated imagemagick package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Tue, 10 Apr 2012 17:24:02 +0200
Source: imagemagick
Binary: imagemagick imagemagick-dbg imagemagick-common imagemagick-doc libmagickcore5 libmagickcore5-extra libmagickcore-dev libmagickwand5 libmagickwand-dev libmagick++5 libmagick++-dev perlmagick
Architecture: source amd64 all
Version: 8:6.7.4.0-4
Distribution: unstable
Urgency: high
Maintainer: ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>
Changed-By: Bastien Roucariès <roucaries.bastien+debian@gmail.com>
Description: 
 imagemagick - image manipulation programs
 imagemagick-common - image manipulation programs -- infrastructure
 imagemagick-dbg - debugging symbols for ImageMagick
 imagemagick-doc - document files of ImageMagick
 libmagick++-dev - object-oriented C++ interface to ImageMagick - development files
 libmagick++5 - object-oriented C++ interface to ImageMagick
 libmagickcore-dev - low-level image manipulation library - development files
 libmagickcore5 - low-level image manipulation library
 libmagickcore5-extra - low-level image manipulation library - extra codecs
 libmagickwand-dev - image manipulation library - development files
 libmagickwand5 - image manipulation library
 perlmagick - Perl interface to the ImageMagick graphics routines
Closes: 667635
Changes: 
 imagemagick (8:6.7.4.0-4) unstable; urgency=high
 .
   * Fix CVE-2012-0259 / CVE-2012-0260 / CVE-2012-1798 /
   CVE-2012-1610 (Closes: #667635)
   - Vulnerability CVE-2012-0259 can cause a DoS in a system
     via handing JPEG files with invalid EXIF XResolution tag.
   - Vulnerability CVE-2012-0260 can lead to excessive use of
     memory in target system, when processing a malicious JPEG file.
     Excessive use of memory can lead to denial of service.
   - Vulnerability CVE-2012-1798 can cause program to crash when
     reading invalid memory, while parsing EXIF IFD in a TIFF file.
   - Vulnerability CVE-2012-1610 Fix a Potential EXIF Integer Overflow
   * Fix menu file to run display.im6 instead of display (fix lintian warning)
Checksums-Sha1: 
 90c66df5a283f4f30d325873da1fd61e9e889837 2434 imagemagick_6.7.4.0-4.dsc
 864e52435d1398faa605ee975c44f59392a92520 43735 imagemagick_6.7.4.0-4.debian.tar.bz2
 1a6d94d4367e8de4cf711db2fa57a508c3ecdd50 130028 imagemagick_6.7.4.0-4_amd64.deb
 ab9bcfae072e03824df353082163cdb02eb40520 4762214 imagemagick-dbg_6.7.4.0-4_amd64.deb
 e2b58b3218d7c5b68e8cd0efae1651da2446fc5e 175554 imagemagick-common_6.7.4.0-4_all.deb
 447cee930dab09c7b548b7adfb5f9750c4389b88 5576876 imagemagick-doc_6.7.4.0-4_all.deb
 d1fc9159ce3d19406c5e82b3ced6d63cf18dd16d 2040648 libmagickcore5_6.7.4.0-4_amd64.deb
 40eb8ae5dff353ec13f1fb102a4fea5154f91f5e 131524 libmagickcore5-extra_6.7.4.0-4_amd64.deb
 c773167cf969b53cefc80b9de41634726201f292 1361784 libmagickcore-dev_6.7.4.0-4_amd64.deb
 b5124fab160cea86e0c75efc770eadd9249c29ee 447772 libmagickwand5_6.7.4.0-4_amd64.deb
 efd04b25c8970f71f6a32277271a21c7c37cd73f 528644 libmagickwand-dev_6.7.4.0-4_amd64.deb
 97f87b1e618467be24d83097fc6c48b151f7d6e5 224352 libmagick++5_6.7.4.0-4_amd64.deb
 ff5a2c985d10995b3c81f396c1c2eb7509d8465a 274474 libmagick++-dev_6.7.4.0-4_amd64.deb
 e9b54d7f7b192c0926788d7fa3a5a4f465cb810b 241162 perlmagick_6.7.4.0-4_amd64.deb
Checksums-Sha256: 
 6d5a30cb98e4240c38f4609166d82fd5be824cd28022b90029e0b35667c86c2b 2434 imagemagick_6.7.4.0-4.dsc
 15b1755a5ec888b83f8d790b01638d9fd0fb9288aafa46bbac27bd44229117a0 43735 imagemagick_6.7.4.0-4.debian.tar.bz2
 f6eaae6419d0283a92196987fd9194abca3c27a15feeb6b88d6fcb448c12a3a1 130028 imagemagick_6.7.4.0-4_amd64.deb
 565e60582d1fc80898b6abd0675934dee4d670d369b87d819e9e04b459224233 4762214 imagemagick-dbg_6.7.4.0-4_amd64.deb
 7bad6d384c142357348d3dce9f0a6869d3322b33b9c54558f430fedd036651e8 175554 imagemagick-common_6.7.4.0-4_all.deb
 7dfdfdd0af4ee9df9232e4d59ddc9e9ba4738e1aae7416b9d3289e5565a21790 5576876 imagemagick-doc_6.7.4.0-4_all.deb
 0685ccc7973f9388d67a1c5ba10fccd012209ed6e7a6da61faceb433219078c2 2040648 libmagickcore5_6.7.4.0-4_amd64.deb
 b6fd0f272d408231c6257f11c272340164844c5a87fc0826186f81f504a77ba1 131524 libmagickcore5-extra_6.7.4.0-4_amd64.deb
 45f35d0f5df87a91e6f37af5e64ba7a00ac7e92c62dbe6580594d0fc10d71432 1361784 libmagickcore-dev_6.7.4.0-4_amd64.deb
 5dc9e0d57ccbc94331c9ba6827fd5f67fb9bd7848fdf821a847b63bf683d7f32 447772 libmagickwand5_6.7.4.0-4_amd64.deb
 fff98afe23e74754191197192a7324b314df95335869c0ca7a9c1b4cfac8756e 528644 libmagickwand-dev_6.7.4.0-4_amd64.deb
 495b8d50d1df5983140dc0b36f103677ad9d103dcbfcd9be6b227c0dba0266a7 224352 libmagick++5_6.7.4.0-4_amd64.deb
 be874acf4b04dbc09aecf6dc22dee975dd49edf2a81d8b2536d8dab929c6ab5a 274474 libmagick++-dev_6.7.4.0-4_amd64.deb
 c828635c1973a1208f9a8644ed124bcb040e5e8e7d5c4fce6ba7794ef0bb8d38 241162 perlmagick_6.7.4.0-4_amd64.deb
Files: 
 19cede33d2acb4caabfc9f30a7548397 2434 graphics optional imagemagick_6.7.4.0-4.dsc
 be86112b8c55205771ef370571633dcc 43735 graphics optional imagemagick_6.7.4.0-4.debian.tar.bz2
 0f457a324d62ce22ffd55f70aa45631f 130028 graphics optional imagemagick_6.7.4.0-4_amd64.deb
 859792ec510281d735c4061de7cd237a 4762214 debug extra imagemagick-dbg_6.7.4.0-4_amd64.deb
 e4789415be833710533f260d10ccab5b 175554 graphics optional imagemagick-common_6.7.4.0-4_all.deb
 d62bcf6ada70b9fe16891d80eb6b3a35 5576876 doc optional imagemagick-doc_6.7.4.0-4_all.deb
 4716014ba28666ca0c1c37a73c1638b8 2040648 libs optional libmagickcore5_6.7.4.0-4_amd64.deb
 39776b04adf49e02e81edeb5586597ba 131524 libs optional libmagickcore5-extra_6.7.4.0-4_amd64.deb
 232e6d74361731c7afeac6cc37701b72 1361784 libdevel optional libmagickcore-dev_6.7.4.0-4_amd64.deb
 c903e5d241e06ef5ce76737370c52485 447772 libs optional libmagickwand5_6.7.4.0-4_amd64.deb
 9ea4ea2734785f28cf6bab83bfbd23f6 528644 libdevel optional libmagickwand-dev_6.7.4.0-4_amd64.deb
 e3ac1936b6f87e64bbcc177c1152d7c4 224352 libs optional libmagick++5_6.7.4.0-4_amd64.deb
 24ed9f66ec8ab396e68d221e0d6d7d6d 274474 libdevel optional libmagick++-dev_6.7.4.0-4_amd64.deb
 f3a468384cc59a07c16d1a83ee587f93 241162 perl optional perlmagick_6.7.4.0-4_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAk+F9WwACgkQx/UhwSKygsqZswCfcMuv9mXEpvnLD2tEol+A2RPw
GFYAnj1HGRkGqq0S4+qI3aD2mS86IH3I
=jZvE
-----END PGP SIGNATURE-----





Information forwarded to debian-bugs-dist@lists.debian.org, ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>:
Bug#667635; Package imagemagick. (Thu, 12 Apr 2012 19:21:03 GMT) (full text, mbox, link).


Acknowledgement sent to Vincent Fourmond <fourmond@debian.org>:
Extra info received and forwarded to list. Copy sent to ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>. (Thu, 12 Apr 2012 19:21:03 GMT) (full text, mbox, link).


Message #25 received at 667635@bugs.debian.org (full text, mbox, reply):

From: Vincent Fourmond <fourmond@debian.org>
To: 667635@bugs.debian.org, control@bugs.debian.org
Subject: Correctly marking bad versions
Date: Thu, 12 Apr 2012 21:17:08 +0200
found 667635 8:6.7.4.0-3
found 667635 8:6.6.9.7-7
thanks




Marked as found in versions imagemagick/8:6.7.4.0-3. Request was from Vincent Fourmond <fourmond@debian.org> to control@bugs.debian.org. (Thu, 12 Apr 2012 19:21:07 GMT) (full text, mbox, link).


Marked as found in versions imagemagick/8:6.6.9.7-7. Request was from Vincent Fourmond <fourmond@debian.org> to control@bugs.debian.org. (Thu, 12 Apr 2012 19:21:07 GMT) (full text, mbox, link).


Reply sent to Vincent Fourmond <fourmond@debian.org>:
You have taken responsibility. (Wed, 02 May 2012 22:33:17 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <muehlenhoff@univention.de>:
Bug acknowledged by developer. (Wed, 02 May 2012 22:33:17 GMT) (full text, mbox, link).


Message #34 received at 667635-close@bugs.debian.org (full text, mbox, reply):

From: Vincent Fourmond <fourmond@debian.org>
To: 667635-close@bugs.debian.org
Subject: Bug#667635: fixed in imagemagick 8:6.6.0.4-3+squeeze2
Date: Wed, 02 May 2012 22:32:31 +0000
Source: imagemagick
Source-Version: 8:6.6.0.4-3+squeeze2

We believe that the bug you reported is fixed in the latest version of
imagemagick, which is due to be installed in the Debian FTP archive:

imagemagick-dbg_6.6.0.4-3+squeeze2_amd64.deb
  to main/i/imagemagick/imagemagick-dbg_6.6.0.4-3+squeeze2_amd64.deb
imagemagick-doc_6.6.0.4-3+squeeze2_all.deb
  to main/i/imagemagick/imagemagick-doc_6.6.0.4-3+squeeze2_all.deb
imagemagick_6.6.0.4-3+squeeze2.debian.tar.bz2
  to main/i/imagemagick/imagemagick_6.6.0.4-3+squeeze2.debian.tar.bz2
imagemagick_6.6.0.4-3+squeeze2.dsc
  to main/i/imagemagick/imagemagick_6.6.0.4-3+squeeze2.dsc
imagemagick_6.6.0.4-3+squeeze2_amd64.deb
  to main/i/imagemagick/imagemagick_6.6.0.4-3+squeeze2_amd64.deb
libmagick++-dev_6.6.0.4-3+squeeze2_amd64.deb
  to main/i/imagemagick/libmagick++-dev_6.6.0.4-3+squeeze2_amd64.deb
libmagick++3_6.6.0.4-3+squeeze2_amd64.deb
  to main/i/imagemagick/libmagick++3_6.6.0.4-3+squeeze2_amd64.deb
libmagickcore-dev_6.6.0.4-3+squeeze2_amd64.deb
  to main/i/imagemagick/libmagickcore-dev_6.6.0.4-3+squeeze2_amd64.deb
libmagickcore3-extra_6.6.0.4-3+squeeze2_amd64.deb
  to main/i/imagemagick/libmagickcore3-extra_6.6.0.4-3+squeeze2_amd64.deb
libmagickcore3_6.6.0.4-3+squeeze2_amd64.deb
  to main/i/imagemagick/libmagickcore3_6.6.0.4-3+squeeze2_amd64.deb
libmagickwand-dev_6.6.0.4-3+squeeze2_amd64.deb
  to main/i/imagemagick/libmagickwand-dev_6.6.0.4-3+squeeze2_amd64.deb
libmagickwand3_6.6.0.4-3+squeeze2_amd64.deb
  to main/i/imagemagick/libmagickwand3_6.6.0.4-3+squeeze2_amd64.deb
perlmagick_6.6.0.4-3+squeeze2_amd64.deb
  to main/i/imagemagick/perlmagick_6.6.0.4-3+squeeze2_amd64.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 667635@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Vincent Fourmond <fourmond@debian.org> (supplier of updated imagemagick package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Wed, 18 Apr 2012 23:05:08 +0200
Source: imagemagick
Binary: imagemagick imagemagick-dbg imagemagick-doc libmagickcore3 libmagickcore3-extra libmagickcore-dev libmagickwand3 libmagickwand-dev libmagick++3 libmagick++-dev perlmagick
Architecture: source amd64 all
Version: 8:6.6.0.4-3+squeeze2
Distribution: stable-security
Urgency: high
Maintainer: ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>
Changed-By: Vincent Fourmond <fourmond@debian.org>
Description: 
 imagemagick - image manipulation programs
 imagemagick-dbg - debugging symbols for ImageMagick
 imagemagick-doc - document files of ImageMagick
 libmagick++-dev - object-oriented C++ interface to ImageMagick - development files
 libmagick++3 - object-oriented C++ interface to ImageMagick
 libmagickcore-dev - low-level image manipulation library - development files
 libmagickcore3 - low-level image manipulation library
 libmagickcore3-extra - low-level image manipulation library - extra codecs
 libmagickwand-dev - image manipulation library - development files
 libmagickwand3 - image manipulation library
 perlmagick - Perl interface to the ImageMagick graphics routines
Closes: 665007 667635
Changes: 
 imagemagick (8:6.6.0.4-3+squeeze2) stable-security; urgency=high
 .
   * Fix "Invalid validation DoS CVE-2012-1185 / CVE-2012-1186 (incomplete fix)"
   (Closes: #665007)
   * Fix CVE-2012-0259 / CVE-2012-0260 / CVE-2012-1798 /
     CVE-2012-1610 (Closes: #667635)
   - Vulnerability CVE-2012-0259 can cause a DoS in a system
     via handing JPEG files with invalid EXIF XResolution tag.
   - Vulnerability CVE-2012-0260 can lead to excessive use of
     memory in target system, when processing a malicious JPEG file.
     Excessive use of memory can lead to denial of service.
   - Vulnerability CVE-2012-1798 can cause program to crash when
     reading invalid memory, while parsing EXIF IFD in a TIFF file.
   - Vulnerability CVE-2012-1610 Fix a Potential EXIF Integer Overflow
Checksums-Sha1: 
 e2cb845e70cd066986c6cf0cadebf17e8bfad30e 1914 imagemagick_6.6.0.4-3+squeeze2.dsc
 9be53f846b0c17721d6425977c407b353ee870c6 39845 imagemagick_6.6.0.4-3+squeeze2.debian.tar.bz2
 561288cbf24eccb9387c43c3eb4c592142b02ea2 105678 imagemagick_6.6.0.4-3+squeeze2_amd64.deb
 936d6d3eab461b5a8631d5ef8353e11be516bbcc 3691536 imagemagick-dbg_6.6.0.4-3+squeeze2_amd64.deb
 3115ea171278ab5170eec2a52cb75ac2fcf1ccb7 4176596 imagemagick-doc_6.6.0.4-3+squeeze2_all.deb
 3e91dd0748ef1ef31926e2aa80356e5bba774e57 1764922 libmagickcore3_6.6.0.4-3+squeeze2_amd64.deb
 57f7e32677994a75399136623ebe5020b7c7f01e 120952 libmagickcore3-extra_6.6.0.4-3+squeeze2_amd64.deb
 e035b6890f149efb5cc4c988b9f6a842388d3702 1190578 libmagickcore-dev_6.6.0.4-3+squeeze2_amd64.deb
 8c0ad856f61a9ff83dcfdc940758d04b22e5d86b 417792 libmagickwand3_6.6.0.4-3+squeeze2_amd64.deb
 b76abd4437d0bd4c3a2d63532087eefbf47637d1 493638 libmagickwand-dev_6.6.0.4-3+squeeze2_amd64.deb
 728568de5de726211758c4adfb274a2daa3c848b 209606 libmagick++3_6.6.0.4-3+squeeze2_amd64.deb
 0afd88e7604a2eb16c0be75bf6234688010e2166 259554 libmagick++-dev_6.6.0.4-3+squeeze2_amd64.deb
 2cbd39fbd98f5c25a5b1d1bd0b1d7f45f2d37d34 226278 perlmagick_6.6.0.4-3+squeeze2_amd64.deb
Checksums-Sha256: 
 caa7b926865880c7f802d36f7b0b799ea61e127764c41361cc536f77f702c6e9 1914 imagemagick_6.6.0.4-3+squeeze2.dsc
 236a6d5bd5cc20819cea6cd48a05c593035b49b5e0d2b1ed4f4427e9bd7103d5 39845 imagemagick_6.6.0.4-3+squeeze2.debian.tar.bz2
 39ef2a452324d986002f3473a61afe1ce792c993e2db1489488d07fe646c568a 105678 imagemagick_6.6.0.4-3+squeeze2_amd64.deb
 d499387cd3c4d4f2e7cf09b3833954a4b3c8a029224365bbd00f90247c053cbb 3691536 imagemagick-dbg_6.6.0.4-3+squeeze2_amd64.deb
 ff2acc3f4a7512f5ea9e214cfc3b1433bc03365b1699ee6ac230f2a6b5a9bcf6 4176596 imagemagick-doc_6.6.0.4-3+squeeze2_all.deb
 dc6d7f29fffed83a2408c1de4eb429a16038d8092778931feb53880702d1f3ea 1764922 libmagickcore3_6.6.0.4-3+squeeze2_amd64.deb
 c7d175c6a66395b2e26066d5853d028e6b5971048633f977dc45fc8715425554 120952 libmagickcore3-extra_6.6.0.4-3+squeeze2_amd64.deb
 2948d6d98bda4a513a218c72869647f2303eaac4fba1647bffeb90b8a079b403 1190578 libmagickcore-dev_6.6.0.4-3+squeeze2_amd64.deb
 a664cd1b3e78e4eccde7cc8a61c91739747793c3773e61a35df25dcdfbd19f06 417792 libmagickwand3_6.6.0.4-3+squeeze2_amd64.deb
 177777438c53bbf1e935697dc18373428e71a84d6605ffa0410ee2864d2af790 493638 libmagickwand-dev_6.6.0.4-3+squeeze2_amd64.deb
 324f140e45eaacc5cc66e9f6faca16bb99344abc7c79d956ae91d7d2936b9766 209606 libmagick++3_6.6.0.4-3+squeeze2_amd64.deb
 22bce2ee29ab77a5f91f7f947ac0acdbf2c9515cd073f19e5ef57e75d4f94299 259554 libmagick++-dev_6.6.0.4-3+squeeze2_amd64.deb
 1146a1246b6c273b669563feb3a8068ab75f6a4b399ab8cfe7b6d6f240c91f0e 226278 perlmagick_6.6.0.4-3+squeeze2_amd64.deb
Files: 
 d631468b69eacfdf7d6aba560d7bf993 1914 graphics optional imagemagick_6.6.0.4-3+squeeze2.dsc
 79f34c9902d38ab886e8882446efb0be 39845 graphics optional imagemagick_6.6.0.4-3+squeeze2.debian.tar.bz2
 51e5952c660ab180ee97041c1f7f23d3 105678 graphics optional imagemagick_6.6.0.4-3+squeeze2_amd64.deb
 f692d337d2cc10e3ac23365fc3900c51 3691536 debug extra imagemagick-dbg_6.6.0.4-3+squeeze2_amd64.deb
 81e33241b1092de87a021d79f3c20b72 4176596 doc optional imagemagick-doc_6.6.0.4-3+squeeze2_all.deb
 6b567c00b8b91798e98c8506d1739f03 1764922 libs optional libmagickcore3_6.6.0.4-3+squeeze2_amd64.deb
 993eb589e37f6cd4ff51244ff2c02ed2 120952 libs optional libmagickcore3-extra_6.6.0.4-3+squeeze2_amd64.deb
 38b411c0015de2f146607333cde49de0 1190578 libdevel optional libmagickcore-dev_6.6.0.4-3+squeeze2_amd64.deb
 178329c95b35148db5b02d566030a712 417792 libs optional libmagickwand3_6.6.0.4-3+squeeze2_amd64.deb
 3d9852d3c2d63d7290a8230fe473b9b5 493638 libdevel optional libmagickwand-dev_6.6.0.4-3+squeeze2_amd64.deb
 8315ccb5913fc96561f2cd62fc20a3bb 209606 libs optional libmagick++3_6.6.0.4-3+squeeze2_amd64.deb
 c4d30d1a41650124c6b127f9bccc736e 259554 libdevel optional libmagick++-dev_6.6.0.4-3+squeeze2_amd64.deb
 50579e1d3d0c98f3bbba735920f77801 226278 perl optional perlmagick_6.6.0.4-3+squeeze2_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAk+ZkU8ACgkQx/UhwSKygsp0IwCguvsvhNBi/IxwDbt+ctuH8UW/
YVsAn1tKSHhh8puLwqDZ/jDX+st9WIdv
=VkXP
-----END PGP SIGNATURE-----





Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Thu, 31 May 2012 07:36:05 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 16:21:37 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.