imagemagick: CVE-2017-17879: heap-buffer-overflow in ReadOneMNGImage

Related Vulnerabilities: CVE-2017-17879   CVE-2017-1000445   CVE-2017-1000476   CVE-2017-12140   CVE-2017-12674   CVE-2017-12691   CVE-2017-12692   CVE-2017-12693   CVE-2017-12875   CVE-2017-12877   CVE-2017-12983   CVE-2017-13061   CVE-2017-13133   CVE-2017-13134   CVE-2017-13758   CVE-2017-13768   CVE-2017-13769   CVE-2017-14060   CVE-2017-14172   CVE-2017-14173   CVE-2017-14174   CVE-2017-14175   CVE-2017-14224   CVE-2017-14249   CVE-2017-14341   CVE-2017-14400   CVE-2017-14505   CVE-2017-14532   CVE-2017-14607   CVE-2017-14624   CVE-2017-14625   CVE-2017-14626   CVE-2017-14682   CVE-2017-10928   CVE-2017-14739   CVE-2017-14741   CVE-2017-14989   CVE-2017-15015   CVE-2017-15017   CVE-2017-15277   CVE-2017-15281   CVE-2017-16546   CVE-2017-17499   CVE-2017-17504   CVE-2017-17681   CVE-2017-17682   CVE-2017-17914   CVE-2018-5248   CVE-2017-12644   CVE-2017-13058   CVE-2017-13059   CVE-2017-13060   CVE-2017-13062   CVE-2017-13131   CVE-2017-14137   CVE-2017-14138   CVE-2017-14139   CVE-2017-14324   CVE-2017-14325   CVE-2017-14326   CVE-2017-14342   CVE-2017-14343   CVE-2017-14531   CVE-2017-14533   CVE-2017-14684   CVE-2017-15016   CVE-2017-15032   CVE-2017-15033   CVE-2017-15217   CVE-2017-15218   CVE-2017-17680   CVE-2017-17881   CVE-2017-17882   CVE-2017-17883   CVE-2017-17884   CVE-2017-17885   CVE-2017-17886   CVE-2017-17887   CVE-2017-17934   CVE-2017-18008   CVE-2017-18022   CVE-2017-18027   CVE-2017-18028   CVE-2017-18029   CVE-2017-6502   CVE-2018-5246   CVE-2018-5247   CVE-2018-5357   CVE-2018-5358   CVE-2018-6405   CVE-2017-10995   CVE-2017-11533   CVE-2017-11535   CVE-2017-11639   CVE-2017-13143  

Debian Bug report logs - #885125
imagemagick: CVE-2017-17879: heap-buffer-overflow in ReadOneMNGImage

version graph

Reported by: Salvatore Bonaccorso <carnil@debian.org>

Date: Sun, 24 Dec 2017 09:45:01 UTC

Severity: grave

Tags: confirmed, fixed-upstream, patch, security, upstream

Found in versions imagemagick/8:6.9.7.4+dfsg-11, imagemagick/8:6.9.7.4+dfsg-1, imagemagick/8:6.8.9.9-5

Fixed in versions imagemagick/8:6.9.9.34+dfsg-1, imagemagick/8:6.8.9.9-5+deb8u12, imagemagick/8:6.9.7.4+dfsg-11+deb9u4

Done: Moritz Muehlenhoff <jmm@debian.org>

Bug is archived. No further changes may be made.

Forwarded to https://github.com/ImageMagick/ImageMagick/issues/906

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, carnil@debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>:
Bug#885125; Package src:imagemagick. (Sun, 24 Dec 2017 09:45:04 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
New Bug report received and forwarded. Copy sent to carnil@debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>. (Sun, 24 Dec 2017 09:45:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: imagemagick: CVE-2017-17879: heap-buffer-overflow in ReadOneMNGImage
Date: Sun, 24 Dec 2017 10:40:43 +0100
Source: imagemagick
Version: 8:6.9.7.4+dfsg-1
Severity: important
Tags: patch security upstream
Forwarded: https://github.com/ImageMagick/ImageMagick/issues/906

Hi,

the following vulnerability was published for imagemagick.

CVE-2017-17879[0]:
| In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-21, there is a heap-based
| buffer over-read in ReadOneMNGImage in coders/png.c, related to length
| calculation and caused by an off-by-one error.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-17879
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17879
[1] https://github.com/ImageMagick/ImageMagick/issues/906

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



Marked as found in versions imagemagick/8:6.8.9.9-5. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sun, 24 Dec 2017 09:48:03 GMT) (full text, mbox, link).


Marked as found in versions imagemagick/8:6.9.7.4+dfsg-11. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Tue, 26 Dec 2017 14:09:09 GMT) (full text, mbox, link).


Severity set to 'grave' from 'important' Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Thu, 28 Dec 2017 09:45:05 GMT) (full text, mbox, link).


Added tag(s) fixed-upstream. Request was from bts-link-upstream@lists.alioth.debian.org to control@bugs.debian.org. (Thu, 28 Dec 2017 17:12:24 GMT) (full text, mbox, link).


Added tag(s) pending and confirmed. Request was from roucaries.bastien@gmail.com to control@bugs.debian.org. (Thu, 08 Feb 2018 12:18:17 GMT) (full text, mbox, link).


Reply sent to Bastien Roucariès <rouca@debian.org>:
You have taken responsibility. (Fri, 09 Feb 2018 22:40:47 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Fri, 09 Feb 2018 22:40:47 GMT) (full text, mbox, link).


Message #20 received at 885125-close@bugs.debian.org (full text, mbox, reply):

From: Bastien Roucariès <rouca@debian.org>
To: 885125-close@bugs.debian.org
Subject: Bug#885125: fixed in imagemagick 8:6.9.9.34+dfsg-1
Date: Fri, 09 Feb 2018 22:35:40 +0000
Source: imagemagick
Source-Version: 8:6.9.9.34+dfsg-1

We believe that the bug you reported is fixed in the latest version of
imagemagick, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 885125@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Bastien Roucariès <rouca@debian.org> (supplier of updated imagemagick package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 08 Feb 2018 13:38:05 +0100
Source: imagemagick
Binary: imagemagick-6-common imagemagick-6-doc libmagickcore-6-headers libmagickwand-6-headers libmagick++-6-headers libimage-magick-perl libmagickcore-6-arch-config imagemagick-6.q16 libmagickcore-6.q16-5 libmagickcore-6.q16-5-extra libmagickcore-6.q16-dev libmagickwand-6.q16-5 libmagickwand-6.q16-dev libmagick++-6.q16-8 libmagick++-6.q16-dev libimage-magick-q16-perl imagemagick-6.q16hdri libmagickcore-6.q16hdri-5 libmagickcore-6.q16hdri-5-extra libmagickcore-6.q16hdri-dev libmagickwand-6.q16hdri-5 libmagickwand-6.q16hdri-dev libmagick++-6.q16hdri-8 libmagick++-6.q16hdri-dev libimage-magick-q16hdri-perl imagemagick-common imagemagick-doc perlmagick libmagickcore-dev libmagickwand-dev libmagick++-dev imagemagick
Architecture: source
Version: 8:6.9.9.34+dfsg-1
Distribution: experimental
Urgency: high
Maintainer: ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>
Changed-By: Bastien Roucariès <rouca@debian.org>
Description:
 imagemagick - image manipulation programs -- binaries
 imagemagick-6-common - image manipulation programs -- infrastructure
 imagemagick-6-doc - document files of ImageMagick
 imagemagick-6.q16 - image manipulation programs -- quantum depth Q16
 imagemagick-6.q16hdri - image manipulation programs -- quantum depth Q16HDRI
 imagemagick-common - image manipulation programs -- infrastructure dummy package
 imagemagick-doc - document files of ImageMagick -- dummy package
 libimage-magick-perl - Perl interface to the ImageMagick graphics routines
 libimage-magick-q16-perl - Perl interface to the ImageMagick graphics routines -- Q16 versio
 libimage-magick-q16hdri-perl - Perl interface to the ImageMagick graphics routines -- Q16HDRI ve
 libmagick++-6-headers - object-oriented C++ interface to ImageMagick - header files
 libmagick++-6.q16-8 - C++ interface to ImageMagick -- quantum depth Q16
 libmagick++-6.q16-dev - C++ interface to ImageMagick - development files (Q16)
 libmagick++-6.q16hdri-8 - C++ interface to ImageMagick -- quantum depth Q16HDRI
 libmagick++-6.q16hdri-dev - C++ interface to ImageMagick - development files (Q16HDRI)
 libmagick++-dev - object-oriented C++ interface to ImageMagick -- dummy package
 libmagickcore-6-arch-config - low-level image manipulation library - architecture header files
 libmagickcore-6-headers - low-level image manipulation library - header files
 libmagickcore-6.q16-5 - low-level image manipulation library -- quantum depth Q16
 libmagickcore-6.q16-5-extra - low-level image manipulation library - extra codecs (Q16)
 libmagickcore-6.q16-dev - low-level image manipulation library - development files (Q16)
 libmagickcore-6.q16hdri-5 - low-level image manipulation library -- quantum depth Q16HDRI
 libmagickcore-6.q16hdri-5-extra - low-level image manipulation library - extra codecs (Q16HDRI)
 libmagickcore-6.q16hdri-dev - low-level image manipulation library - development files (Q16HDRI
 libmagickcore-dev - low-level image manipulation library -- dummy package
 libmagickwand-6-headers - image manipulation library - headers files
 libmagickwand-6.q16-5 - image manipulation library -- quantum depth Q16
 libmagickwand-6.q16-dev - image manipulation library - development files (Q16)
 libmagickwand-6.q16hdri-5 - image manipulation library -- quantum depth Q16HDRI
 libmagickwand-6.q16hdri-dev - image manipulation library - development files (Q16HDRI)
 libmagickwand-dev - image manipulation library -- dummy package
 perlmagick - Perl interface to ImageMagick -- dummy package
Closes: 856601 872373 872609 873059 873099 873100 873131 873134 873871 875338 875339 875341 875352 875502 875503 875504 875506 876097 876099 876105 876487 876488 877354 877355 878506 878507 878508 878524 878527 878541 878545 878546 878547 878548 878554 878555 878562 878578 878579 878679 881392 884444 885125 885339 885340 885941 885942 886281 886584 886588
Changes:
 imagemagick (8:6.9.9.34+dfsg-1) experimental; urgency=high
 .
   * New upstream version
   * Packaging fix:
     + Fix privacy breach.
     + Bump compat level to 11.
     + Bump policy no changes
     + Fix lintian warnings
     + Fix "unnecessary libgraphviz-dev dependency (and graphviz
       suggests?)", thanks to Matthias Klose (Closes: #884444).
     + Remove Vincent Fourmond <fourmond@debian.org> as uploader, thanks
       to him. (Closes: #878679).
     + Aknowledge NMU (Closes: #856601)
   * Fix a few security issues
     + Fix CVE-2017-1000445: NULL pointer dereference in
       the MagickCore component and might lead to denial of service.
       (Closes: #886281)
     + Fix CVE-2017-1000476: a CPU exhaustion vulnerability was found in
       the function ReadDDSInfo in coders/dds.c, which allows attackers
       to cause a denial of service.
     + Fix CVE-2017-12140: The ReadDCMImage function in coders\dcm.c
       has an integer signedness error leading to excessive memory
       consumption via a crafted DCM file.
       (Closes: #873059)
     + Fix CVE-2017-12674: a CPU exhaustion vulnerability was found in
       the function ReadPDBImage in coders/pdb.c, which allows attackers
       to cause a denial of service
       (Closes: #872609)
     + Fix CVE-2017-12691: The ReadOneLayer function in coders/xcf.c
       allows remote attackers to cause a denial of service
       (memory consumption) via a crafted file.
       (Closes: #875338)
     + Fix CVE-2017-12692: ReadVIFFImage function in coders/viff.c
       in ImageMagick allows remote attackers to cause a
       denial of service (memory consumption) via a crafted VIFF file.
       (Closes: #875339)
     + Fix CVE-2017-12693: The ReadBMPImage function in coders/bmp.c
       allows remote attackers to cause a denial of service
       (memory consumption) via a crafted BMP
       (Closes: #875341)
     + Fix CVE-2017-12875: The WritePixelCachePixels function
       allows remote attackers to cause a denial of service
       (CPU consumption) via a crafted file.
       (Closes: #873871)
     + Fix CVE-2017-12877: Use-after-free vulnerability in
       the DestroyImage function in image.c in ImageMagick allows
       remote attackers to cause a denial of service via a crafted file.
       (Closes: #872373)
     + Fix CVE-2017-12983: Heap-based buffer overflow in the ReadSFWImage
       function in coders/sfw.c in ImageMagick 7.0.6-8 allows remote
       attackers to cause a denial of service (application crash)
       or possibly have unspecified other impact via a crafted file.
       (Closes: #873134)
     + Fix CVE-2017-13061: A length-validation vulnerability was found
       in the function ReadPSDLayersInternal in coders/psd.c,
       which allows attackers to cause a denial of service
       (ReadPSDImage memory exhaustion) via a crafted file
       (Closes: #873131)
     + Fix CVE-2017-13133: the load_level function in coders/xcf.c lacks
       offset validation, which allows attackers to cause a denial of service
       (load_tile memory exhaustion) via a crafted file.
       (Closes: #873100)
     + Fix CVE-2017-13134: a heap-based buffer over-read was found in the
       function SFWScan in coders/sfw.c, which allows attackers
       to cause a denial of service via a crafted file.
       (Closes: #873099)
     + Fix CVE-2017-13758: a heap-based buffer overflow in the TracePoint()
       function in MagickCore/draw.c.
       (Closes: #878508)
     + Fix CVE-2017-13768: NULL Pointer Dereference in the IdentifyImage
       function in MagickCore/identify.c in ImageMagick allows an attacker
       to perform denial of service by sending a crafted image file.
       (Closes: #875352)
     + Fix CVE-2017-13769: The WriteTHUMBNAILImage function in
       coders/thumbnail.c allows an attacker to cause a denial of service
       (buffer over-read) by sending a crafted JPEG file.
       (Closes: #878507)
     + Fix CVE-2017-14060: a NULL Pointer Dereference issue is present in the
       ReadCUTImage function in coders/cut.c that could allow an attacker
       to cause a Denial of Service (in the QueueAuthenticPixelCacheNexus
       function within the MagickCore/cache.c file) by submitting
       a malformed image file.
       (Closes: #878506)
     + Fix CVE-2017-14172: In coders/ps.c, a DoS in ReadPSImage()
       due to lack of an EOF (End of File) check cause high CPU consumption.
       When a crafted PSD file, which claims a large "extent" field
       in the header but does not contain sufficient backing data,
       is provided, the loop over "length" would consume huge CPU resources,
       since there is no EOF check inside the loop.
       (Closes: #875506)
     + Fix CVE-2017-14173: In the function ReadTXTImage() in coders/txt.c,
       an integer overflow might occur for the addition operation
       "GetQuantumRange(depth)+1" when "depth" is large, producing a smaller
       value than expected. As a result, an infinite loop would occur
       for a crafted TXT file that claims a very large "max_value" value.
       (Closes: #875504)
     + Fix CVE-2017-14174: In coders/psd.c in ReadPSDLayersInternal()
       a lack of an EOF (End of File) check might cause huge CPU consumption.
       When a crafted PSD file, which claims a large "length" field
       in the header but does not contain sufficient backing data,
       is provided, the loop over "length" would consume huge CPU resources,
       since there is no EOF check inside the loop.
       (Closes: #875503)
     + Fix CVE-2017-14175: In coders/xbm.c in ReadXBMImage()
       a lack of an EOF (End of File) check might cause huge CPU consumption.
       When a crafted XBM file, which claims large rows and columns fields
       in the header but does not contain sufficient backing data,
       is provided, the loop over the rows would consume huge CPU resources,
       since there is no EOF check inside the loop.
       (Closes: #875502)
     + Fix CVE-2017-14224: A heap-based buffer overflow in WritePCXImage
       in coders/pcx.c allows remote attackers to cause a denial
       of service or code execution via a crafted file.
       (Closes: #876097)
     + Fix CVE-2017-14249: Imagemagick mishandles EOF checks in
       ReadMPCImage in coders/mpc.c, leading to division by zero
       in GetPixelCacheTileSize in MagickCore/cache.c,
       allowing remote attackers to cause a denial of service
       via a crafted file.
       (Closes: #876099)
     + Fix CVE-2017-14341: large loop vulnerability in ReadWPGImage
       in coders/wpg.c, causing CPU exhaustion via a crafted
       wpg image file.
       (Closes: #876105)
     + Fix CVE-2017-14400: PersistPixelCache function in magick/cache.c
       mishandles the pixel cache nexus, which allows remote attackers
       to cause a denial of service (NULL pointer dereference
       in the function GetVirtualPixels in MagickCore/cache.c)
       via a crafted file.
       (Closes: #878546)
     + Fix CVE-2017-14505: DrawGetStrokeDashArray in wand/drawing-wand.c
       mishandles certain NULL arrays, which allows attackers to perform
       Denial of Service (NULL pointer dereference and application crash in
       AcquireQuantumMemory within MagickCore/memory.c) by providing a
       crafted Image File as input.
       (Closes: #878545)
     + Fix CVE-2017-14532: NULL Pointer Dereference in TIFFIgnoreTags
       in coders/tiff.c.
       (Closes: #878541)
     + Fix CVE-2017-14607: out of bounds read flaw related to ReadTIFFImage
       has been reported in coders/tiff.c. An attacker could possibly
       exploit this flaw to disclose potentially sensitive memory
       or cause an application crash.
       (Closes: #878527)
     + Fix CVE-2017-14624: a NULL Pointer Dereference vulnerability
       in the function PostscriptDelegateMessage in coders/ps.c.
       (Closes: #877354)
     + Fix CVE-2017-14625: NULL Pointer Dereference vulnerability
       in the function sixel_output_create in coders/sixel.c.
       (Closes: #877355)
     + Fix CVE-2017-14626: NULL Pointer Dereference vulnerability
       in the function sixel_decode in coders/sixel.c.
       (Closes: #878524)
     + Fix CVE-2017-14682: GetNextToken in MagickCore/token.c
       allows remote attackers to cause a denial of service
       (heap-based buffer overflow and application crash)
       or possibly have unspecified other impact via a
       crafted SVG document, a different vulnerability
       than CVE-2017-10928.
       (Closes: #876488)
     + Fix CVE-2017-14739: The AcquireResampleFilterThreadSet
       function in magick/resample-private.h in ImageMagick
       mishandles failed memory allocation, which allows
       remote attackers to cause a denial of service
       (NULL Pointer Dereference in DistortImage in
       MagickCore/distort.c, and application crash)
       via unspecified vectors.
       (Closes: #878547)
     + Fix CVE-2017-14741: The ReadCAPTIONImage function in coders/caption.c
       allows remote attackers to cause a denial of service
       (infinite loop) via a crafted font file.
       (Closes: #878548)
     + Fix CVE-2017-14989: A use-after-free in RenderFreetype
       in MagickCore/annotate.c allows attackers to crash the application
       via a crafted font file, because the FT_Done_Glyph function
       (from FreeType 2) is called at an incorrect place in the ImageMagick code.
       (Closes: #878562)
     + Fix CVE-2017-15015: NULL pointer dereference vulnerability in
       PDFDelegateMessage in coders/pdf.c.
       (Closes: #878555)
     + Fix CVE-2017-15017: NULL pointer dereference vulnerability
       in ReadOneMNGImage in coders/png.c.
       (Closes: #878554)
     + Fix CVE-2017-15277: ReadGIFImage in coders/gif.c leaves
       the palette uninitialized when processing a GIF file that has
       neither a global nor local palette. If the affected product is
       used as a library loaded into a process that operates on
       interesting data, this data sometimes can be leaked
       via the uninitialized palette.
       (Closes: #878578)
     + Fix CVE-2017-15281: ReadPSDImage in coders/psd.c
       allows remote attackers to cause a denial of service
       (application crash) or possibly have unspecified other impact
       via a crafted file, related to "Conditional jump or move
       depends on uninitialised value(s).
       (Closes: #878579).
     + Fix CVE-2017-16546: The ReadWPGImage function in coders/wpg.c
       does not properly validate the colormap index in a WPG palette,
       which allows remote attackers to cause a denial of service
       (use of uninitialized data or invalid memory allocation)
       or possibly have unspecified other impact via a malformed WPG file.
       (Closes: #881392)
     + Fix CVE-2017-17499: use-after-free in Magick::Image::read
       in Magick++/lib/Image.cpp.
       (Closes: #885339)
     + Fix CVE-2017-17504: coders/png.c Magick_png_read_raw_profile
       heap-based buffer over-read via a crafted file, related to
       ReadOneMNGImage.
       (Closes: #885340)
     + Fix CVE-2017-17681: an infinite loop vulnerability was found
       in the function ReadPSDChannelZip in coders/psd.c, which
       allows attackers to cause a denial of service (CPU exhaustion)
       via a crafted psd image file.
       (Closes: #885941)
     + Fix CVE-2017-17682: large loop vulnerability was found in the
       function ExtractPostscript in coders/wpg.c, which allows attackers
       to cause a denial of service (CPU exhaustion) via a crafted wpg
       image file that triggers a ReadWPGImage call.
       (Closes: #885942)
     + Fix CVE-2017-17879: a heap-based buffer over-read in ReadOneMNGImage
       in coders/png.c, related to length calculation and caused by an
       off-by-one error.
       (Closes: #885125)
     + Fix CVE-2017-17914: a vulnerability was found in the function
       ReadOnePNGImage in coders/png.c, which allows attackers to cause
       a denial of service (ReadOneMNGImage large loop) via a crafted mng
       image file.
       (Closes: #886584)
     + Fix CVE-2018-5248: a heap-based buffer over-read in coders/sixel.c
       in the ReadSIXELImage function, related to the sixel_decode function.
       (Closes: #886588)
   * Fix a few unimportant security bugs:
     + Fix CVE-2017-12644 memory leak vulnerability
       in ReadDCMImage in coders\dcm.c
     + Fix CVE-2017-13058 memory leak in WritePCXImage
     + Fix CVE-2017-13059 memory leak in WriteJNGImage
     + Fix CVE-2017-13060 memory leak in ReadMATImage
     + Fix CVE-2017-13062 memory leak vulnerability
       found in the function formatIPTC in coders/meta.c,
       which allows attackers to cause a denial of service
       (WriteMETAImage memory consumption) via a crafted file.
     + Fix CVE-2017-13131 a memory leak vulnerability
       found in the function ReadMIFFImage in coders/miff.c,
       which allows attackers to cause a denial of service
       (memory consumption in NewLinkedList in MagickCore/linked-list.c)
       via a crafted file.
     + Fix CVE-2017-14137: ReadWEBPImage in coders/webp.c has an issue
       where memory allocation is excessive,
       because it depends only on a length field in a header.
     + Fix CVE-2017-14138: ReadWEBPImage in coders/webp.c
       because memory is not freed in certain error cases.
     + Fix CVE-2017-14139: memory leak vulnerability
       in WriteMSLImage in coders/msl.c.
     + Fix CVE-2017-14324: memory leak in ReadMPCImage (coders/mpc.c)
     + Fix CVE-2017-14325: memory leak in ReadMPCImage (coders/mpc.c)
     + Fix CVE-2017-14326: memory leak vulnerability in the function
       ReadMATImage in coders/mat.c, which allows attackers
       to cause a denial of service via a crafted file.
     + Fix CVE-2017-14342: memory exhaustion vulnerability in
       ReadWPGImage in coders/wpg.c via a crafted wpg image file.
     + Fix CVE-2017-14343: memory leak vulnerability in
       ReadXCFImage in coders/xcf.c via a crafted xcf image file.
     + Fix CVE-2017-14531: memory exhaustion issue in
       ReadSUNImage in coders/sun.c.
     + Fix CVE-2017-14533: memory leak in ReadMATImage in coders/mat.c.
     + Fix CVE-2017-14684: mory leak vulnerability was found in the
       function ReadVIPSImage in coders/vips.c, which allows
       attackers to cause a denial of service (memory consumption
       in ResizeMagickMemory in MagickCore/memory.c) via a crafted file.
       (Closes: #876487)
     + Fix CVE-2017-15016: a NULL pointer dereference vulnerability
       in ReadEnhMetaFile in coders/emf.c. (source fix not compiled
       under Debian).
     + Fix CVE-2017-15032: memory leak in ReadYCBCRImage in
       coders/ycbcr.c.
     + Fix CVE-2017-15033: memory leak in ReadYUVImage in coders/yuv.c.
     + Fix CVE-2017-15217: memory leak in ReadSGIImage in coders/sgi.c.
     + Fix CVE-2017-15218: memory leak in ReadOneJNGImage in coders/png.c.
     + Fix CVE-2017-17680: a memory leak vulnerability was found in
       the function ReadXPMImage in coders/xpm.c, which allows
       attackers to cause a denial of service via a crafted xpm image file.
     + Fix CVE-2017-17881: a memory leak vulnerability was found in
       the function ReadMATImage in coders/mat.c, which allows
       attackers to cause a denial of service via a crafted MAT image file.
     + Fix CVE-2017-17882: a memory leak vulnerability was found in the
       function ReadXPMImage in coders/xpm.c, which allows attackers
       to cause a denial of service via a crafted XPM image file.
     + Fix CVE-2017-17883: a memory leak vulnerability was found in the
       function ReadPGXImage in coders/pgx.c, which allows attackers
       to cause a denial of service via a crafted PGX image file.
     + Fix CVE-2017-17884: a memory leak vulnerability was found in the
       function WriteOnePNGImage in coders/png.c,
       which allows attackers to cause a denial of service via
       a crafted PNG image file.
     + Fix CVE-2017-17885: a memory leak vulnerability was found
       in the function ReadPICTImage in coders/pict.c, which
       allows attackers to cause a denial of service via a crafted
       PICT image file.
     + Fix CVE-2017-17886: a memory leak vulnerability was found
       in the function ReadPSDChannelZip in coders/psd.c,
       which allows attackers to cause a denial of service
       via a crafted psd image file.
     + Fix CVE-2017-17887: a memory leak vulnerability
       was found in the function GetImagePixelCache in magick/cache.c,
       which allows attackers to cause a denial of service via a crafted
       MNG image file that is processed by ReadOneMNGImage.
     + Fix CVE-2017-17934: a memory leaks in coders/msl.c,
       related to MSLPopImage and ProcessMSLScript,
       and associated with mishandling of MSLPushImage calls.
     + Fix CVE-2017-18008: a ùemory Leak in ReadPWPImage in coders/pwp.c.
     + Fix CVE-2017-18022: memory leaks in MontageImageCommand
       in MagickWand/montage.c.
     + Fix CVE-2017-18027: a memory leak vulnerability was found
       in the function ReadMATImage in coders/mat.c,
       which allow remote attackers to cause a denial
       of service via a crafted file.
     + Fix CVE-2017-18028: a memory exhaustion vulnerability
       was found in the function ReadTIFFImage in coders/tiff.c,
       which allow remote attackers to cause a denial
       of service via a crafted file.
     + Fix CVE-2017-18029: a memory leak vulnerability was found
       in the function ReadMATImage in coders/mat.c,
       which allow remote attackers to cause a denial of
       service via a crafted file.
     + Fix CVE-2017-6502: a specially crafted webp file
       could lead to a file-descriptor leak in libmagickcore
       (thus, a DoS)
     + Fix CVE-2018-5246: Fix memory leaks in ReadPATTERNImage
       in coders/pattern.c.
     + Fix CVE-2018-5247: Fix memory leaks in ReadRLAImage in coders/rla.c.
     + Fix CVE-2018-5357: Fix memory leaks in the ReadDCMImage function
       in coders/dcm.c.
     + Fix CVE-2018-5358: Fix memory leaks in the EncodeImageAttributes
       function in coders/json.c, as demonstrated by the
       ReadPSDLayersInternal function in coders/psd.c.
   * Backport fix:
     + Fix CVE-2018-6405: In the ReadDCMImage function in coders/dcm.c
       in ImageMagick before 7.0.7-23, each redmap, greenmap, and bluemap
       variable can be overwritten by a new pointer.
       The previous pointer is lost, which leads to a memory leak.
       This allows remote attackers to cause a denial of service.
       (from b0a464122e0d8a1e1e31f6cd6d3f4d085fa8fb0)
Checksums-Sha1:
 019151a2eed984c20284cd3430d0cea81fa618e6 5122 imagemagick_6.9.9.34+dfsg-1.dsc
 bac50ed3a85fa095472370d57f9c76c88a0e445a 9047920 imagemagick_6.9.9.34+dfsg.orig.tar.xz
 205d49483312479b02ca7ca9da28ef44714f446f 218000 imagemagick_6.9.9.34+dfsg-1.debian.tar.xz
 e759d647494139eeb4f0f130264085c4b7a538bc 29140 imagemagick_6.9.9.34+dfsg-1_amd64.buildinfo
Checksums-Sha256:
 201b79b2f8337c30216f6c918d0040b4d5c0d460bba36162f324ac78d55e9b5e 5122 imagemagick_6.9.9.34+dfsg-1.dsc
 ef0554a2e27cc8d039da5f7c6178bc889a896f3892d7d3ee48fc83cad579b590 9047920 imagemagick_6.9.9.34+dfsg.orig.tar.xz
 e63ce64ca2364c4bdb1cce8c10d1dffe92598615cb7d937fa0b057446bbc614a 218000 imagemagick_6.9.9.34+dfsg-1.debian.tar.xz
 fe9909a20a00867089a25b70631f32ba26a7c5441e0f07b2fcb2ffae905fe545 29140 imagemagick_6.9.9.34+dfsg-1_amd64.buildinfo
Files:
 4ab0613bdfae5e8b1aa46d3854d636ea 5122 graphics optional imagemagick_6.9.9.34+dfsg-1.dsc
 2fb2d6622e1ab0ca0182a00089ad1dff 9047920 graphics optional imagemagick_6.9.9.34+dfsg.orig.tar.xz
 33ca0bae16ca48676b3853fcaad6de9f 218000 graphics optional imagemagick_6.9.9.34+dfsg-1.debian.tar.xz
 a7012245af4ed8de530066d85bee46ca 29140 graphics optional imagemagick_6.9.9.34+dfsg-1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAlp+HVAACgkQADoaLapB
CF9IBg//YV9mQaUY5n7rLLfMqV+eyM0gDIbHQzQ5YAS8rc8cRAExPV4tKBk7TT9S
yJkuKKkxSgYIPzdnQH5kkxmf1ddv0XYSWdLgUQxnSFkp2FdaVEbXwSqoVT8sMSVj
XAEY93sStNXVaXoeY0IjRY+9jw6rsKXmWcd5x4sg77UZ5SJms4D4EFAplIzRWCV+
kk0uV6EEWlOZzOeBTENoDGhvm6wXUZ39vPXk0+j6kJFKjAt143hPj/Oltmn8UkrL
YIvEEr1hjMExoo1AWl80YiVGoBg08jgU+TGGbeDsXnxdwBZc2rVUHbHFKXhOP+x2
j6v8Xc5+RhgUODXs2aThmB/MnXoirxAG/yXoHCDRkLGg/7d8AEGzm9XCmlbIvtss
HCM4cHaIsPnigh7TsA4kJzfFscaXVtYyilUnSiYVzby16RdXE8ydZwUedIQOezSU
3fovU9zhXQgD/btBKf4Lc5Mup4mZ08jSHC79IjiB6ja2Fqe0uoVBf2ZW4XLpUCrd
7rwTtorHuBwyfbEmDFl0DJKvAtW4KnJHonkGnKSrX7zLFh49hv1I/afzolbhsOG4
5o4pFY6MynuwNpakHgWukKF96EBsR4Wztx6XZm+CPpfKSMfzGZ7ODidEoW/YFnP1
g15vtUlNjl+Yt+JOHFQ13VhyyYELNMPWZGK2xKGHdYZc5to6gh0=
=+P95
-----END PGP SIGNATURE-----




Reply sent to Markus Koschany <apo@debian.org>:
You have taken responsibility. (Sun, 20 May 2018 20:36:06 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Sun, 20 May 2018 20:36:06 GMT) (full text, mbox, link).


Message #25 received at 885125-close@bugs.debian.org (full text, mbox, reply):

From: Markus Koschany <apo@debian.org>
To: 885125-close@bugs.debian.org
Subject: Bug#885125: fixed in imagemagick 8:6.8.9.9-5+deb8u12
Date: Sun, 20 May 2018 20:32:38 +0000
Source: imagemagick
Source-Version: 8:6.8.9.9-5+deb8u12

We believe that the bug you reported is fixed in the latest version of
imagemagick, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 885125@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Markus Koschany <apo@debian.org> (supplier of updated imagemagick package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 06 May 2018 18:28:48 +0200
Source: imagemagick
Binary: imagemagick-common imagemagick-doc libmagickcore-6-headers libmagickwand-6-headers libmagick++-6-headers imagemagick libimage-magick-perl libmagickcore-6-arch-config imagemagick-6.q16 libmagickcore-6.q16-2 libmagickcore-6.q16-2-extra libmagickcore-6.q16-dev libmagickwand-6.q16-2 libmagickwand-6.q16-dev libmagick++-6.q16-5 libmagick++-6.q16-dev imagemagick-dbg libimage-magick-q16-perl perlmagick libmagickcore-dev libmagickwand-dev libmagick++-dev
Architecture: source all amd64
Version: 8:6.8.9.9-5+deb8u12
Distribution: jessie-security
Urgency: high
Maintainer: ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>
Changed-By: Markus Koschany <apo@debian.org>
Description:
 imagemagick - image manipulation programs -- binaries
 imagemagick-6.q16 - image manipulation programs -- quantum depth Q16
 imagemagick-common - image manipulation programs -- infrastructure
 imagemagick-dbg - debugging symbols for ImageMagick
 imagemagick-doc - document files of ImageMagick
 libimage-magick-perl - Perl interface to the ImageMagick graphics routines
 libimage-magick-q16-perl - Perl interface to the ImageMagick graphics routines -- Q16 versio
 libmagick++-6-headers - object-oriented C++ interface to ImageMagick - header files
 libmagick++-6.q16-5 - object-oriented C++ interface to ImageMagick
 libmagick++-6.q16-dev - object-oriented C++ interface to ImageMagick - development files
 libmagick++-dev - object-oriented C++ interface to ImageMagick
 libmagickcore-6-arch-config - low-level image manipulation library - architecture header files
 libmagickcore-6-headers - low-level image manipulation library - header files
 libmagickcore-6.q16-2 - low-level image manipulation library -- quantum depth Q16
 libmagickcore-6.q16-2-extra - low-level image manipulation library - extra codecs (Q16)
 libmagickcore-6.q16-dev - low-level image manipulation library - development files (Q16)
 libmagickcore-dev - low-level image manipulation library -- transition package
 libmagickwand-6-headers - image manipulation library - headers files
 libmagickwand-6.q16-2 - image manipulation library
 libmagickwand-6.q16-dev - image manipulation library - development files
 libmagickwand-dev - image manipulation library - transition for development files
 perlmagick - Perl interface to ImageMagick -- transition package
Closes: 867748 869827 869834 870012 870065 885125 885340 886588
Changes:
 imagemagick (8:6.8.9.9-5+deb8u12) jessie-security; urgency=high
 .
   * Non-maintainer upload.
   * Fix the following security vulnerabilities:
     - CVE-2017-10995: heap-based buffer over-read and application crash via a
       crafted MNG image. (Closes: #867748)
     - CVE-2017-11533: heap-based buffer over-read in the WriteUILImage()
       function in coders/uil.c. (Closes: #869834)
     - CVE-2017-11535: heap-based buffer over-read in the WritePSImage()
       function in coders/ps.c. (Closes: #869827)
     - CVE-2017-11639: heap-based buffer over-read in the WriteCIPImage()
       function in coders/cip.c. (Closes: #870065)
     - CVE-2017-13143: ReadMATImage function in coders/mat.c uses uninitialized
       data, which might allow remote attackers to obtain sensitive information
       from process memory. (Closes: #870012)
     - CVE-2017-17504: heap-based buffer over-read. (Closes: #885340)
     - CVE-2017-17879: heap-based buffer over-read in ReadOneMNGImage
       in coders/png.c. (Closes: #885125)
     - CVE-2018-5248: heap-based buffer over-read in coders/sixel.c
       in the ReadSIXELImage function. (Closes: #886588)
Checksums-Sha1:
 468888952a648e60c22ed2071c8b263b43a2ef17 3883 imagemagick_6.8.9.9-5+deb8u12.dsc
 b9a73542db8e8a52f9d444d40b08bbf05180fdf5 297216 imagemagick_6.8.9.9-5+deb8u12.debian.tar.xz
 7d1b53ab4c0c22d369eaf7f618ba3303ef74d7cd 153984 imagemagick-common_6.8.9.9-5+deb8u12_all.deb
 54e3d1aef5cf770e4523a80eba2cbfbe78b9eb13 7649652 imagemagick-doc_6.8.9.9-5+deb8u12_all.deb
 8af5c50393a803ff79a95af7a3cac99de596c6bf 172510 libmagickcore-6-headers_6.8.9.9-5+deb8u12_all.deb
 bf641b907b374f872c32d7c4ff4ac892d489f9a3 135508 libmagickwand-6-headers_6.8.9.9-5+deb8u12_all.deb
 dcf7f5ec7bed48f1dfa2f2250208943585f083ef 171222 libmagick++-6-headers_6.8.9.9-5+deb8u12_all.deb
 b371668633b2bad3772878d0d0d3359e0bacfd55 160400 imagemagick_6.8.9.9-5+deb8u12_amd64.deb
 95874f7c9c53ad3b0382f4a5f6655a171b2056de 179032 libimage-magick-perl_6.8.9.9-5+deb8u12_all.deb
 f5691f86f910e9ad6c349c201d9d75c8ed1a16a1 134292 libmagickcore-6-arch-config_6.8.9.9-5+deb8u12_amd64.deb
 7af263aedc031474cda83ea2e7faf13698a3a136 514544 imagemagick-6.q16_6.8.9.9-5+deb8u12_amd64.deb
 6c729d6a7a2e5fa52ba2ec194927b5f2c24c1411 1696444 libmagickcore-6.q16-2_6.8.9.9-5+deb8u12_amd64.deb
 94295f944492efdfd24a7eb20eaa1cbc17b80918 175104 libmagickcore-6.q16-2-extra_6.8.9.9-5+deb8u12_amd64.deb
 89e36cd0784a2fa9707f5d27aa86bfc4431a0dc4 1032490 libmagickcore-6.q16-dev_6.8.9.9-5+deb8u12_amd64.deb
 649dca53bb18eb0e4ff829537be5391613ca9371 409098 libmagickwand-6.q16-2_6.8.9.9-5+deb8u12_amd64.deb
 13ca625e5ffcc27d34fe1326094e216fdb489140 395068 libmagickwand-6.q16-dev_6.8.9.9-5+deb8u12_amd64.deb
 f48db5b4c77d9e8ed4cb2bf0066b2f393fa583a1 259716 libmagick++-6.q16-5_6.8.9.9-5+deb8u12_amd64.deb
 d21d398c80a0f9e4c7c495abece08055ee707ec7 226406 libmagick++-6.q16-dev_6.8.9.9-5+deb8u12_amd64.deb
 a240ce1387ce607654b3e82a335a43cd23885e5b 5012968 imagemagick-dbg_6.8.9.9-5+deb8u12_amd64.deb
 47a22cd542474e21406237360f590a082aa2e429 225488 libimage-magick-q16-perl_6.8.9.9-5+deb8u12_amd64.deb
 6634a242eee3c00ff6dbc841a52dd44a4ae87dc1 126830 perlmagick_6.8.9.9-5+deb8u12_all.deb
 b39cd2025ab0a8c14f84d7df6d5bd3f36a256354 126814 libmagickcore-dev_6.8.9.9-5+deb8u12_all.deb
 ec82f7a1c0daf7113257d7353c786fe8ea20599f 126796 libmagickwand-dev_6.8.9.9-5+deb8u12_all.deb
 e744a72149d400e358741beef81070954cf7ce18 126826 libmagick++-dev_6.8.9.9-5+deb8u12_all.deb
Checksums-Sha256:
 38f76f398784f7540a20b8bc44c84fa1fb47391518d4a7f192575f4a1dc7f852 3883 imagemagick_6.8.9.9-5+deb8u12.dsc
 4373d71c5c3b45f598bbec094bd00320070144113a26a458abed09ae40aa7ce8 297216 imagemagick_6.8.9.9-5+deb8u12.debian.tar.xz
 c0c56277e22c394d82d95ec4dc35cda0f985f67f1d733f06daf6ab1f4af10338 153984 imagemagick-common_6.8.9.9-5+deb8u12_all.deb
 9063218f43686b8ac2ef939c6f1ed297a085309e002d43aa79dd95169bbf1593 7649652 imagemagick-doc_6.8.9.9-5+deb8u12_all.deb
 234f28438b6737f810df6ff414aa8e58e96408173c6e6dfd204c06c0df4273c4 172510 libmagickcore-6-headers_6.8.9.9-5+deb8u12_all.deb
 d0d5fc232f2a2121cb9072528ef12b96e25f6454d7197b88f4d9414288acc293 135508 libmagickwand-6-headers_6.8.9.9-5+deb8u12_all.deb
 daafb76df6f5475a5a8e4d99774592fba9362fd241337ab67f6a9da35e31c291 171222 libmagick++-6-headers_6.8.9.9-5+deb8u12_all.deb
 c0e3a1b501d3d06a9667266b0635d04cde1ee83ca9282366b91b31565daa3b33 160400 imagemagick_6.8.9.9-5+deb8u12_amd64.deb
 d58aee72427d237915dfbbb22beabc46e7a7c4df1e287f15a7de01a298e9dbd3 179032 libimage-magick-perl_6.8.9.9-5+deb8u12_all.deb
 c8bac2da9aea6f454b4984c11c00ac0becc6b63548995b1137020e346559a2a5 134292 libmagickcore-6-arch-config_6.8.9.9-5+deb8u12_amd64.deb
 be21eb245ebd01b9a0e9ca3c56bb884540bfa67858792ca3971beee555005d7c 514544 imagemagick-6.q16_6.8.9.9-5+deb8u12_amd64.deb
 0f84e65a217daa4defa702d7ef9688853a33244d1eda9408ccff94e38f975958 1696444 libmagickcore-6.q16-2_6.8.9.9-5+deb8u12_amd64.deb
 082697ebc346ca39893ce13ed8d013569e777e69865aaacad89299d569a12736 175104 libmagickcore-6.q16-2-extra_6.8.9.9-5+deb8u12_amd64.deb
 e93a471db7574c21ee59155fc556b3e37ace21a9b0903507c0263b4e9e0b32b8 1032490 libmagickcore-6.q16-dev_6.8.9.9-5+deb8u12_amd64.deb
 352463767c6427a14718900319089fc399f548a58dea28f38221cd38115b57ec 409098 libmagickwand-6.q16-2_6.8.9.9-5+deb8u12_amd64.deb
 12174608be0ee3afaed80540e102f8f944fdc47b85a16b5349a9e327019ad92c 395068 libmagickwand-6.q16-dev_6.8.9.9-5+deb8u12_amd64.deb
 86e6243e9df2c9356cf85bcef42178ca92ce6a386568d460644f1ada64109047 259716 libmagick++-6.q16-5_6.8.9.9-5+deb8u12_amd64.deb
 a0991b41cad7204a3c51046ca014f70ebf9b1869b4d7cdec14008733bc353eae 226406 libmagick++-6.q16-dev_6.8.9.9-5+deb8u12_amd64.deb
 8984b081c93765af5673109029a7ee691be992eb3e7c1c56b870a65af5e44997 5012968 imagemagick-dbg_6.8.9.9-5+deb8u12_amd64.deb
 7daf4fedadac202aea4432779aa40e57f614b0b5a5bce47da94b9e9d400c2c69 225488 libimage-magick-q16-perl_6.8.9.9-5+deb8u12_amd64.deb
 ea3b74bcc999dd1cf7d4d943bb81d1f7403ebece56cc91d85863418523fe7f32 126830 perlmagick_6.8.9.9-5+deb8u12_all.deb
 d1161f11dcc5381973110e5c85e07ce352bdbb19f06dbb078f1c5983a4ae28e6 126814 libmagickcore-dev_6.8.9.9-5+deb8u12_all.deb
 0b9b8e0ecf47a8781633860da2969838bd9de8665d6ff2c1815a04bca397182b 126796 libmagickwand-dev_6.8.9.9-5+deb8u12_all.deb
 3e881b1bfd9a0ef1ac83dc8086f97b41a110aff7170a81736464782a707f9dd7 126826 libmagick++-dev_6.8.9.9-5+deb8u12_all.deb
Files:
 3ce7edf902d784cd189dac2febce00a8 3883 graphics optional imagemagick_6.8.9.9-5+deb8u12.dsc
 ba653e742f8c94fff61d9c7b23061e84 297216 graphics optional imagemagick_6.8.9.9-5+deb8u12.debian.tar.xz
 15ea0900cfd71400f7dba25bddaa6e36 153984 graphics optional imagemagick-common_6.8.9.9-5+deb8u12_all.deb
 c0951637b1fc2c3619e939ef839f3b49 7649652 doc optional imagemagick-doc_6.8.9.9-5+deb8u12_all.deb
 d5a5658815ce46e5a5ca8e417f68e2c1 172510 libdevel optional libmagickcore-6-headers_6.8.9.9-5+deb8u12_all.deb
 f1ee0e9dbdd254003b4d9d00726a1ece 135508 libdevel optional libmagickwand-6-headers_6.8.9.9-5+deb8u12_all.deb
 c8aada52d8b0caf50e69b3d6c3fd6438 171222 libdevel optional libmagick++-6-headers_6.8.9.9-5+deb8u12_all.deb
 bc87299dcd9bb6dba11e196509a00634 160400 graphics optional imagemagick_6.8.9.9-5+deb8u12_amd64.deb
 26a0166852024cfd331494b737b00907 179032 perl optional libimage-magick-perl_6.8.9.9-5+deb8u12_all.deb
 73544e47afd5cfdd84d585c51ae4a58b 134292 libdevel optional libmagickcore-6-arch-config_6.8.9.9-5+deb8u12_amd64.deb
 f1519035c65964bc6e05560ba1b25dde 514544 graphics optional imagemagick-6.q16_6.8.9.9-5+deb8u12_amd64.deb
 a2c28b71be787b01a5b8b67315a3eda4 1696444 libs optional libmagickcore-6.q16-2_6.8.9.9-5+deb8u12_amd64.deb
 f714762c681c181ef1ebd1d629e471d9 175104 libs optional libmagickcore-6.q16-2-extra_6.8.9.9-5+deb8u12_amd64.deb
 cfa9b9aafee296b6ec6d14f217754740 1032490 libdevel optional libmagickcore-6.q16-dev_6.8.9.9-5+deb8u12_amd64.deb
 89307d59fe56ae2e7f0f7ad4b5cfae92 409098 libs optional libmagickwand-6.q16-2_6.8.9.9-5+deb8u12_amd64.deb
 885ffc6a95c54e860e9793d22a0d5480 395068 libdevel optional libmagickwand-6.q16-dev_6.8.9.9-5+deb8u12_amd64.deb
 a00a340d26a445cac9d17faf076d0446 259716 libs optional libmagick++-6.q16-5_6.8.9.9-5+deb8u12_amd64.deb
 b475f54d683cbb2f57e045cd8e475429 226406 libdevel optional libmagick++-6.q16-dev_6.8.9.9-5+deb8u12_amd64.deb
 a96d000d914433ea1ce8ba3891092dd9 5012968 debug extra imagemagick-dbg_6.8.9.9-5+deb8u12_amd64.deb
 ae5cbfd1b51a6faf58a85d381a00a951 225488 perl optional libimage-magick-q16-perl_6.8.9.9-5+deb8u12_amd64.deb
 718331679148dc15e479add78fdadd69 126830 oldlibs extra perlmagick_6.8.9.9-5+deb8u12_all.deb
 2a244dfa630bbc918fa8bff6b7b6f5e7 126814 oldlibs extra libmagickcore-dev_6.8.9.9-5+deb8u12_all.deb
 994807b9baa964b8f2629aed0cdcbe74 126796 oldlibs extra libmagickwand-dev_6.8.9.9-5+deb8u12_all.deb
 6e3fdc3f00c83f3ef4ab08ba4850fa43 126826 oldlibs extra libmagick++-dev_6.8.9.9-5+deb8u12_all.deb

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEEAqSkbVtrXP4xJMh4EL6Jg/PVnWQFAlr+ysIACgkQEL6Jg/PV
nWShpQgAuhzhrp7Nh4OD/eZa6yCORBd8UDWStHPxyOjqQDwsyutTDHEPaXazG4tt
mwzSubxlGQAvKj2dZ3zcuhJo+coryojdm/jUTYC6Ou4vcc5nY1NgvgdajB3VPtiV
PGoAOYXLw2Nvz8vFikEr0NhjAtvcQdj6T8/SGDG3twBiVmzoFt21nKpuPBDdXDYE
4DWulbXQXQIKlgd51940MNAct9zHJ0PXBGQnnV79oTQi03MbVi8EKO48TFxZ5BUC
I6Nx3onRsAn8PeYc4k7Zg5i2v+/Qbh4SMhQHY6fa0b/EQE2dA2CqXlG2rI1X8+XD
j1gKdRJhk8SFs5o25hnvkIXt5hVr8Q==
=CJdP
-----END PGP SIGNATURE-----




Reply sent to Moritz Muehlenhoff <jmm@debian.org>:
You have taken responsibility. (Sat, 14 Jul 2018 21:06:07 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Sat, 14 Jul 2018 21:06:07 GMT) (full text, mbox, link).


Message #30 received at 885125-close@bugs.debian.org (full text, mbox, reply):

From: Moritz Muehlenhoff <jmm@debian.org>
To: 885125-close@bugs.debian.org
Subject: Bug#885125: fixed in imagemagick 8:6.9.7.4+dfsg-11+deb9u4
Date: Sat, 14 Jul 2018 21:02:11 +0000
Source: imagemagick
Source-Version: 8:6.9.7.4+dfsg-11+deb9u4

We believe that the bug you reported is fixed in the latest version of
imagemagick, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 885125@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Moritz Muehlenhoff <jmm@debian.org> (supplier of updated imagemagick package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 26 Dec 2017 12:24:39 +0000
Source: imagemagick
Binary: imagemagick-6-common imagemagick-6-doc libmagickcore-6-headers libmagickwand-6-headers libmagick++-6-headers libimage-magick-perl libmagickcore-6-arch-config imagemagick-6.q16 libmagickcore-6.q16-3 libmagickcore-6.q16-3-extra libmagickcore-6.q16-dev libmagickwand-6.q16-3 libmagickwand-6.q16-dev libmagick++-6.q16-7 libmagick++-6.q16-dev libimage-magick-q16-perl imagemagick-6.q16hdri libmagickcore-6.q16hdri-3 libmagickcore-6.q16hdri-3-extra libmagickcore-6.q16hdri-dev libmagickwand-6.q16hdri-3 libmagickwand-6.q16hdri-dev libmagick++-6.q16hdri-7 libmagick++-6.q16hdri-dev libimage-magick-q16hdri-perl imagemagick-common imagemagick-doc perlmagick libmagickcore-dev libmagickwand-dev libmagick++-dev imagemagick
Architecture: source all amd64
Version: 8:6.9.7.4+dfsg-11+deb9u4
Distribution: stretch-security
Urgency: medium
Maintainer: ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org>
Changed-By: Moritz Muehlenhoff <jmm@debian.org>
Description:
 imagemagick - image manipulation programs -- binaries
 imagemagick-6-common - image manipulation programs -- infrastructure
 imagemagick-6-doc - document files of ImageMagick
 imagemagick-6.q16 - image manipulation programs -- quantum depth Q16
 imagemagick-6.q16hdri - image manipulation programs -- quantum depth Q16HDRI
 imagemagick-common - image manipulation programs -- infrastructure dummy package
 imagemagick-doc - document files of ImageMagick -- dummy package
 libimage-magick-perl - Perl interface to the ImageMagick graphics routines
 libimage-magick-q16-perl - Perl interface to the ImageMagick graphics routines -- Q16 versio
 libimage-magick-q16hdri-perl - Perl interface to the ImageMagick graphics routines -- Q16HDRI ve
 libmagick++-6-headers - object-oriented C++ interface to ImageMagick - header files
 libmagick++-6.q16-7 - C++ interface to ImageMagick -- quantum depth Q16
 libmagick++-6.q16-dev - C++ interface to ImageMagick - development files (Q16)
 libmagick++-6.q16hdri-7 - C++ interface to ImageMagick -- quantum depth Q16HDRI
 libmagick++-6.q16hdri-dev - C++ interface to ImageMagick - development files (Q16HDRI)
 libmagick++-dev - object-oriented C++ interface to ImageMagick -- dummy package
 libmagickcore-6-arch-config - low-level image manipulation library - architecture header files
 libmagickcore-6-headers - low-level image manipulation library - header files
 libmagickcore-6.q16-3 - low-level image manipulation library -- quantum depth Q16
 libmagickcore-6.q16-3-extra - low-level image manipulation library - extra codecs (Q16)
 libmagickcore-6.q16-dev - low-level image manipulation library - development files (Q16)
 libmagickcore-6.q16hdri-3 - low-level image manipulation library -- quantum depth Q16HDRI
 libmagickcore-6.q16hdri-3-extra - low-level image manipulation library - extra codecs (Q16HDRI)
 libmagickcore-6.q16hdri-dev - low-level image manipulation library - development files (Q16HDRI
 libmagickcore-dev - low-level image manipulation library -- dummy package
 libmagickwand-6-headers - image manipulation library - headers files
 libmagickwand-6.q16-3 - image manipulation library -- quantum depth Q16
 libmagickwand-6.q16-dev - image manipulation library - development files (Q16)
 libmagickwand-6.q16hdri-3 - image manipulation library -- quantum depth Q16HDRI
 libmagickwand-6.q16hdri-dev - image manipulation library - development files (Q16HDRI)
 libmagickwand-dev - image manipulation library -- dummy package
 perlmagick - Perl interface to ImageMagick -- dummy package
Closes: 872373 881392 885125
Changes:
 imagemagick (8:6.9.7.4+dfsg-11+deb9u4) stretch-security; urgency=medium
 .
   * CVE-2017-12877 (Closes: #872373)
   * CVE-2017-16546 (Closes: #881392)
   * CVE-2017-17499
   * CVE-2017-17504
   * CVE-2017-17879 (Closes: #885125)
Checksums-Sha1:
 82138f2f1ad37c081fe147d7cd7e86790ebc12c7 5165 imagemagick_6.9.7.4+dfsg-11+deb9u4.dsc
 4aed4a29633d383d9a6f19b7a40a4d20b9f4d5c5 242484 imagemagick_6.9.7.4+dfsg-11+deb9u4.debian.tar.xz
 cc9086a7840ba3dabe5015713c2cf2ddc2116f17 184394 imagemagick-6-common_6.9.7.4+dfsg-11+deb9u4_all.deb
 b20949dc5c7dc6c310e71e85ebd20c1cd14fc6c9 7527666 imagemagick-6-doc_6.9.7.4+dfsg-11+deb9u4_all.deb
 877214cfd53c74ce416c62d5d7f2af4dc9e63bc1 92438 imagemagick-6.q16-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 b939522f331f21347f77651cdc26e293ca03389f 562530 imagemagick-6.q16_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 c4172f5e871e60d7f2b08fb1f143e72b139cd8a5 92418 imagemagick-6.q16hdri-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 eaa2d30b5c57b42a0c6ceff7be551dade307b6c5 562784 imagemagick-6.q16hdri_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 69a3c69427c578bf68416a99fd88bd0ec591f0a8 1404 imagemagick-common_6.9.7.4+dfsg-11+deb9u4_all.deb
 1ed04cc819e81cfe4c22339d43b6df200ab82b25 1452 imagemagick-doc_6.9.7.4+dfsg-11+deb9u4_all.deb
 5f9cc3b9246fa88b5136260a4bf568681d8a1514 29316 imagemagick_6.9.7.4+dfsg-11+deb9u4_amd64.buildinfo
 48f95c6dc42a4fe6f98f9f6276f071be55891bec 141218 imagemagick_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 bc7bbbe0bd91782d51dee16dee7c31c309775eeb 53278 libimage-magick-perl_6.9.7.4+dfsg-11+deb9u4_all.deb
 c327ce594fe69390cc41de14412456cf0f222449 189140 libimage-magick-q16-perl-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 c73e4e1d40b7eef5e1627cbd66a50dd3a5ca624b 224538 libimage-magick-q16-perl_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 5f417db1dc201a18615c1e5c0a1651997f12883f 188240 libimage-magick-q16hdri-perl-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 855ce1db9bf7fa1c16b9786e5253a312178bd7fc 224850 libimage-magick-q16hdri-perl_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 f8f94e7254f68249c1ead8364b093014143112cf 47126 libmagick++-6-headers_6.9.7.4+dfsg-11+deb9u4_all.deb
 40bef2b9042fb1d944076a2d425d4769181e72ad 984910 libmagick++-6.q16-7-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 c24aa8ccc31e8234f72a228127e59b0d37cb4906 272848 libmagick++-6.q16-7_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 e1eee12c13d7db2ed27382a869fc78cecaff125a 245796 libmagick++-6.q16-dev_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 9bdc4ee86fc52757646358019ec2baac3ae88b1f 984368 libmagick++-6.q16hdri-7-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 15023bd2120e64d3de356b81f04e042ac08fc5d6 257462 libmagick++-6.q16hdri-7_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 73b67f311f4a9e510ca9d37beffd84af09d98e1d 246508 libmagick++-6.q16hdri-dev_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 e0685c8a71fe63403101100d46657647dc6ce349 1292 libmagick++-dev_6.9.7.4+dfsg-11+deb9u4_all.deb
 40eaa1212c64f3441d4a2f0cc21e23859e045ebd 148666 libmagickcore-6-arch-config_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 3a66aa095f73fb0cbec99d90193202799ee2baff 46930 libmagickcore-6-headers_6.9.7.4+dfsg-11+deb9u4_all.deb
 14c3b65d36c53948aa03493fd1633ffac03ef0a6 4448774 libmagickcore-6.q16-3-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 c70407e7bb8f777d1428e0e31d28a46ec9f0159a 174324 libmagickcore-6.q16-3-extra-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 02ecf6abd602b3aeaa5b8d16ea4aeb3b5f0b089b 190212 libmagickcore-6.q16-3-extra_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 b49b7ef34452233b483cb90409b6be4cdbb93fe7 1742152 libmagickcore-6.q16-3_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 da01132e319e5870d3b97579e7cae9bcfa4c5a08 1093222 libmagickcore-6.q16-dev_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 570fe82c480b544a6fc154ff8d36c9b5b27cbce2 4428512 libmagickcore-6.q16hdri-3-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 efdcd586fc27f5d3352a4abc5f1d675bae79ed6f 174054 libmagickcore-6.q16hdri-3-extra-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 302dba9be1c3a35908c0da7737581238f90b9414 190094 libmagickcore-6.q16hdri-3-extra_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 6ee49b891643daf1c35cac72aa0cfca0562e30bb 1749536 libmagickcore-6.q16hdri-3_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 e3194c1d4d1caab663635d6b9c6f33dc2016efa8 1088438 libmagickcore-6.q16hdri-dev_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 208674109ea17b09b9b6caa036c66c89d0485123 1256 libmagickcore-dev_6.9.7.4+dfsg-11+deb9u4_all.deb
 e737e9ec1197cbdb9dc2bd88c2d3ab2aa3c2f4f1 10466 libmagickwand-6-headers_6.9.7.4+dfsg-11+deb9u4_all.deb
 ac374b298012e362391c584e67f51f0647a5e3fd 672624 libmagickwand-6.q16-3-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 76c44d4efee3db5749b63cf80d5fdbb6f61482d4 421516 libmagickwand-6.q16-3_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 d3c212e4f8713bc7018bc84d59bb3dde2b5a55f4 417200 libmagickwand-6.q16-dev_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 ab7256fc482638775c32cc0b4d63f9f17ab9bdfc 669032 libmagickwand-6.q16hdri-3-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 df5c325d29e57ef6b980aafa2d16687d523a519b 420768 libmagickwand-6.q16hdri-3_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 6d7c1efc395d8eb5ccbee050ecf039e0a545d18e 417338 libmagickwand-6.q16hdri-dev_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 f8f5fdbaf29def1c8872912eb372542957f62aef 1246 libmagickwand-dev_6.9.7.4+dfsg-11+deb9u4_all.deb
 1480f4179824fecc4076cde1f0f1e4aca0836227 1264 perlmagick_6.9.7.4+dfsg-11+deb9u4_all.deb
Checksums-Sha256:
 85b6fcfe761d7eb32cc5068abd0c798664435c29f5b086fec01ae2d62148a3f3 5165 imagemagick_6.9.7.4+dfsg-11+deb9u4.dsc
 52b97e69d5787b95e7d1af761764461d1b762b15bb76456be99d8153fe2075c4 242484 imagemagick_6.9.7.4+dfsg-11+deb9u4.debian.tar.xz
 aa9108dd66d76f85bd35c84573df3e224308af47fc4f2f501bcda6553aba401d 184394 imagemagick-6-common_6.9.7.4+dfsg-11+deb9u4_all.deb
 38f3ff5f550285f3d962a19cba6ad468efec2d52a4ebbecdfb194efc30c7986b 7527666 imagemagick-6-doc_6.9.7.4+dfsg-11+deb9u4_all.deb
 7947cbaf7bcda30b3f3fac06178cbd292773bae764799cdf9bd453de868a7f09 92438 imagemagick-6.q16-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 cc2421272ff9288acbb1779311f583bb0f889fc3ebe99796afb9f93864f07bfe 562530 imagemagick-6.q16_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 73a6cfc3cc518224613d410a40af36bbeb6c132160a05360b3b4737d2937dc82 92418 imagemagick-6.q16hdri-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 0a61029adaab25ffa28ab19c8b23de04c8b6c4d32bc1455d53faf2d566bb70b4 562784 imagemagick-6.q16hdri_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 1166d0be1623c45d36e9b398e80179ee66aadd77c696a9c18a63b12cf045bf5d 1404 imagemagick-common_6.9.7.4+dfsg-11+deb9u4_all.deb
 f7d3f2c9d871e22dceb4f649b0d6fd10361eda9ed3fb318869fdd13294ed2f25 1452 imagemagick-doc_6.9.7.4+dfsg-11+deb9u4_all.deb
 93425091ea75573b5ad2bf099f23d3b45d6a892758488c1c8dc7369270bdf24d 29316 imagemagick_6.9.7.4+dfsg-11+deb9u4_amd64.buildinfo
 a37d42d046c234306590f3335d220f0da986a28b9c52eae706ca37ee1a84e188 141218 imagemagick_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 b30bf21ecaf31e771daac9f9b538f155fd1e22929a1f24fa38a0e287a223e2e3 53278 libimage-magick-perl_6.9.7.4+dfsg-11+deb9u4_all.deb
 ca4c617c2f6ec0a2a65cb318b4f9d87e5ff8ae516aa2adbecc943acd53371d8b 189140 libimage-magick-q16-perl-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 69f4baea431f968ff28e67086accb08525bd668511076e0b87644cfc49d3f3f6 224538 libimage-magick-q16-perl_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 a67f82859f49c5dad07a07c48e85102a10f9184e72b2afc846782332fdcf065e 188240 libimage-magick-q16hdri-perl-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 34ceef57294f5a597f5190ac204258fd2547249404d223b5363f9dc03018863a 224850 libimage-magick-q16hdri-perl_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 2e42e28623ab0621c3e0f17112f044a935633b0b998430d141920df697e02cf6 47126 libmagick++-6-headers_6.9.7.4+dfsg-11+deb9u4_all.deb
 7c7b221260ac72ad8d2896af2e0a6c62dba7423e6ba62940c1ae935b9facf3eb 984910 libmagick++-6.q16-7-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 72bef86aa880ebcc96941873c98057182afaba01460e95989210dc80d8217621 272848 libmagick++-6.q16-7_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 de8cc51d09a92b3f2a3d83d4e1265419d8c27e39cc106f7ece21f0d36111e021 245796 libmagick++-6.q16-dev_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 650315a610a379a52aa5b3e8ef698b85d8b4303c98618dea1b7f52d0f7756e7b 984368 libmagick++-6.q16hdri-7-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 08e1a4a4fc95673a00ae3904dccfe41c9fa0456ef1f41542e4ee2ff7cfff7602 257462 libmagick++-6.q16hdri-7_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 d0cd92dad0e7e28dd4a694e8342a3c5f20ced85b3efe791e5c4d3d93ada3afea 246508 libmagick++-6.q16hdri-dev_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 bb3826a32b967724dfc195b8389bd754977ba68f97e098b664ff165dcbeb4c05 1292 libmagick++-dev_6.9.7.4+dfsg-11+deb9u4_all.deb
 696762aa7aa9712728d13f465e0a3fd59a38b22f42aa9efad13a51c08b07a556 148666 libmagickcore-6-arch-config_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 0cc7e59a8cfa52d055e1a515d633ab110ae37d413653ecead2ca938492ed4556 46930 libmagickcore-6-headers_6.9.7.4+dfsg-11+deb9u4_all.deb
 4434ee560d30f9dda54b6e83ff1c1b569a48f345356cc03172265339e9842dfd 4448774 libmagickcore-6.q16-3-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 15c5e929d58731c394d34feccd0fee754cd6ce8d3a74e884f1e5fa77ad611cb9 174324 libmagickcore-6.q16-3-extra-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 55c258707b2564a869385939d15b90140fc89ed28579aff267090215b46adff7 190212 libmagickcore-6.q16-3-extra_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 71453bde3a97a39e5b31c71cb7838b0c5090d7651d1f578679ca531a7e27bf6d 1742152 libmagickcore-6.q16-3_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 26039b0014f967794bb584f5c7696a46890b5d8d4add7c020336bf5f5ce906bb 1093222 libmagickcore-6.q16-dev_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 d9db0aa35f3ae1a7a00fd6bdd41e2c7defaa95fc08de6d77a534448f68271a79 4428512 libmagickcore-6.q16hdri-3-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 7d851e9a80ac5e6ce4460664cc658534b391ff8598f6bbcd6e82c84d14393894 174054 libmagickcore-6.q16hdri-3-extra-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 967260d04f1bfb77c593788b16774cfeea6dade68a9fcea438a9082e946816ef 190094 libmagickcore-6.q16hdri-3-extra_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 c274b44fb9424ef764a2e8cddc10c6cf96f23e8d701f7a956d5a701fb10ded15 1749536 libmagickcore-6.q16hdri-3_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 002986b92f0d43a2d046da8d3e367a140830df1ae888715de70cccbb610b39e2 1088438 libmagickcore-6.q16hdri-dev_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 bd12fb2ed10d8d6a28ea38f8edf5199c277814e7f63ef0c89be2f2a93945dfce 1256 libmagickcore-dev_6.9.7.4+dfsg-11+deb9u4_all.deb
 dc13b25413f13e135985356d4f57008d2cf3a10cf202f0ff057a62d19c20cc4a 10466 libmagickwand-6-headers_6.9.7.4+dfsg-11+deb9u4_all.deb
 989bfbe71acea42ec64523aafcc98ffea4d4224033a19e6074dec1b4e47a8f28 672624 libmagickwand-6.q16-3-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 d1933af7172907c23da31a88b4232b9b38ebeffbfaa6e326a7f605fce8d4dc26 421516 libmagickwand-6.q16-3_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 1ecdb6b005cb725ca8c2db3f8a23eed4b203b1cda5957763424d90c1b3f98099 417200 libmagickwand-6.q16-dev_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 bdefa6a870caa4b218033876fe498488de5ef915fd9e79594a83a0d27929a2ca 669032 libmagickwand-6.q16hdri-3-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 f50662b91c754d961d701b902bb1d66eb7ffe2e83953e1f3535d0b9ef1254d4b 420768 libmagickwand-6.q16hdri-3_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 96e43ca18734064492aa25708541e0e7ad2b064b604e360529763417a24ef71f 417338 libmagickwand-6.q16hdri-dev_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 1cab300502b5721d4f146a1432608ea684724de4f13ee106be0712cd801f373e 1246 libmagickwand-dev_6.9.7.4+dfsg-11+deb9u4_all.deb
 5cf87135ab8e92bee3826e510edcb297361b10d27c44d4fd774049045c2435e2 1264 perlmagick_6.9.7.4+dfsg-11+deb9u4_all.deb
Files:
 398b3013f5eee3594d1efa8d3f588520 5165 graphics optional imagemagick_6.9.7.4+dfsg-11+deb9u4.dsc
 96427772ed3ce4aafa72ba0743afcb93 242484 graphics optional imagemagick_6.9.7.4+dfsg-11+deb9u4.debian.tar.xz
 1aad30eb6e802d7cff7471ab0433c987 184394 graphics optional imagemagick-6-common_6.9.7.4+dfsg-11+deb9u4_all.deb
 3f5552e3f54788804851cbca3be21df8 7527666 doc optional imagemagick-6-doc_6.9.7.4+dfsg-11+deb9u4_all.deb
 88b459cee379d4702f3f983d709a4fa9 92438 debug extra imagemagick-6.q16-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 f40571fe5c9dc457e544d14bc9f5a96a 562530 graphics optional imagemagick-6.q16_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 4eff965950d78bc3779fb0582ec2d79e 92418 debug extra imagemagick-6.q16hdri-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 b1245542a04d3d3bd9ef53c0a9e49230 562784 graphics optional imagemagick-6.q16hdri_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 4063d1dd0e9df514b68151d86e545701 1404 oldlibs extra imagemagick-common_6.9.7.4+dfsg-11+deb9u4_all.deb
 c152f76fa9576980c041e8a7bf907fe9 1452 oldlibs extra imagemagick-doc_6.9.7.4+dfsg-11+deb9u4_all.deb
 3e3bb766ebc4e4df148ba79d14bd643a 29316 graphics optional imagemagick_6.9.7.4+dfsg-11+deb9u4_amd64.buildinfo
 eda39da2f3f94f081eb54355a4b95d52 141218 oldlibs extra imagemagick_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 4eb4d6f0d1b1889321ae85f534f73bd2 53278 perl optional libimage-magick-perl_6.9.7.4+dfsg-11+deb9u4_all.deb
 b8b3dc15a8d1a775d01ccd49110c825f 189140 debug extra libimage-magick-q16-perl-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 0cdeafc5dd02d129f5b2f11f39e2a9c5 224538 perl optional libimage-magick-q16-perl_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 7cb09d6ee46964d8c09546be9c12edf2 188240 debug extra libimage-magick-q16hdri-perl-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 0a2a41e217aaf9bcc8fc639c210a91fb 224850 perl optional libimage-magick-q16hdri-perl_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 640c92a52e9fa019b4ab058ffc6526e7 47126 libdevel optional libmagick++-6-headers_6.9.7.4+dfsg-11+deb9u4_all.deb
 ed6c0e1b02c5731ac9e1bc56d4de4d1e 984910 debug extra libmagick++-6.q16-7-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 e8628a073306478135d5ed73dc33a12a 272848 libs optional libmagick++-6.q16-7_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 45813fec32be438368ed4f35eb8dca45 245796 libdevel optional libmagick++-6.q16-dev_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 bcab0f1ebb490a54bb03785fd2438a7c 984368 debug extra libmagick++-6.q16hdri-7-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 fdd1fe62a5011029b9b2d436ce3665d3 257462 libs optional libmagick++-6.q16hdri-7_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 7ed21829c2cafb6802b6e0ad4126d31e 246508 libdevel optional libmagick++-6.q16hdri-dev_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 4c214edf5a45dba66445c17eae50ba07 1292 oldlibs extra libmagick++-dev_6.9.7.4+dfsg-11+deb9u4_all.deb
 6552db598003d0a32345f454ab3427c7 148666 libdevel optional libmagickcore-6-arch-config_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 89c03a824f182833e97cdd796ce1ad76 46930 libdevel optional libmagickcore-6-headers_6.9.7.4+dfsg-11+deb9u4_all.deb
 f19330a7cc292f24c6a70f05959bdb86 4448774 debug extra libmagickcore-6.q16-3-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 21c85effb89d01dbf822c5f2b6b23f0b 174324 debug extra libmagickcore-6.q16-3-extra-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 3ae5d140f0c573e2e248ad9e68f46497 190212 libs optional libmagickcore-6.q16-3-extra_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 db006893ede31aa228199d4f562df1ba 1742152 libs optional libmagickcore-6.q16-3_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 b56c4daa2e8fd176ef39ef57546dc090 1093222 libdevel optional libmagickcore-6.q16-dev_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 a3139c8ce477fe751613e9ebe142176d 4428512 debug extra libmagickcore-6.q16hdri-3-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 0473e08b33008249bb68503a8e67ff4a 174054 debug extra libmagickcore-6.q16hdri-3-extra-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 8ab296918eb16a76459435054287b9ab 190094 libs optional libmagickcore-6.q16hdri-3-extra_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 15d2039d66136b9ce24bdf1e39ba8e67 1749536 libs optional libmagickcore-6.q16hdri-3_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 bd0a643ef06077a96c514be7f6398139 1088438 libdevel optional libmagickcore-6.q16hdri-dev_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 a9534549e543f051307df908d7c6615d 1256 oldlibs extra libmagickcore-dev_6.9.7.4+dfsg-11+deb9u4_all.deb
 d6cd482ea5eef169284bc77744f67617 10466 libdevel optional libmagickwand-6-headers_6.9.7.4+dfsg-11+deb9u4_all.deb
 ccbdc904df1996c38b1dc9aa1df0420f 672624 debug extra libmagickwand-6.q16-3-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 8ceb738d01fb6ac56af9e714e51378b4 421516 libs optional libmagickwand-6.q16-3_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 69269dd86ea0010a584eb845dcd2e1f1 417200 libdevel optional libmagickwand-6.q16-dev_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 3e21f38fb995bdee9de061541def5ac5 669032 debug extra libmagickwand-6.q16hdri-3-dbgsym_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 11f077a2e97940b0947082e8355cb342 420768 libs optional libmagickwand-6.q16hdri-3_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 ca0554aa9e05d3ff04ec7d88c0931500 417338 libdevel optional libmagickwand-6.q16hdri-dev_6.9.7.4+dfsg-11+deb9u4_amd64.deb
 d569939e0e19f202ee9424fd3f982b63 1246 oldlibs extra libmagickwand-dev_6.9.7.4+dfsg-11+deb9u4_all.deb
 227d4b9e97384f7f524c494b17cdec36 1264 oldlibs extra perlmagick_6.9.7.4+dfsg-11+deb9u4_all.deb

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlpCTFMACgkQEMKTtsN8
TjY5LRAAmTRy1x82UxFpTQ5L/2qw/qzTYYh5DnZFdYSA0WvzUwAdF+2hIE4f2B7f
NOnZ58lkRfgu6e1YtBQZMXcGGRZIWe7T00q5Le50BkGHgNfFs5AtbryecnQWZiuA
oFVEaVwZzGZpEXpqNFLcvF0lVO5eF2V8c9W0Sf8cG4bzzsa2YwuYsgQXDiBy7Qf+
3GRzSy3V3yqcWF8rqOt5icLj3uwobMQVU4rRVdWNzCK+i4XiyFVGrRt2JuuTDZjH
dwhpUXxwSnoCSfiAFjJt44GR5m58GViS6uqXFcJC2ydU/aZwH106G2Y6Lk53kFfx
PzDs5gskV6F9Tchrw76Trnyam9VmE8Wxg+Co13Yyu3GZ/hnGa6jZ6XHy429DjEil
bHiTg78356LhRM190i4aNGjTfDM1mLzzKssxvqqFECSqmOjfqGdFExa6GXsYTscZ
Zsk8R7HGynT4emy4fTvvU1rzfPwTMaxTLDLlQGzARCWHinLjZjB0wYhEYWGcs8sr
j4iOyGsVgoGf0J4WXxsmn2hOuGtPfPlcDgZcrl26PJZa4Ahrb/FrlPFFSBM/hGWf
InEdYyQpJy0UOR+J4s+pFpENuCyM+NKIsDF/AL4zyupXQSQ8yAOwb6T1iUUnyd6T
9ZMJayVgN+SleSC+OBtDQXDMQ4ZaomUaRSPT37IDh4stUSfxa/E=
=yGFk
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 11 Nov 2018 07:27:48 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 15:55:35 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.