DSA-3863-1 imagemagick -- security update

Related Vulnerabilities: CVE-2017-7606   CVE-2017-7619   CVE-2017-7941   CVE-2017-7943   CVE-2017-8343   CVE-2017-8344   CVE-2017-8345   CVE-2017-8346   CVE-2017-8347   CVE-2017-8348   CVE-2017-8349   CVE-2017-8350   CVE-2017-8351   CVE-2017-8352   CVE-2017-8353   CVE-2017-8354   CVE-2017-8355   CVE-2017-8356   CVE-2017-8357   CVE-2017-8765   CVE-2017-8830   CVE-2017-9098   CVE-2017-9141   CVE-2017-9142   CVE-2017-9143   CVE-2017-9144  

This update fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed RLE, ART, JNG, DDS, BMP, ICO, EPT, SUN, MTV, PICT, XWD, PCD, SFW, MAT, EXR, DCM, MNG, PCX or SVG files are processed. For the stable distribution (jessie), these problems have been fixed in version 8:6.8.9.9-5+deb8u9. For the upcoming stable distribution (stretch), these problems have been fixed in version 8:6.9.7.4+dfsg-8. For the unstable distribution (sid), these problems have been fixed in version 8:6.9.7.4+dfsg-8. We recommend that you upgrade your imagemagick packages.

Debian Security Advisory

DSA-3863-1 imagemagick -- security update

Date Reported:
25 May 2017
Affected Packages:
imagemagick
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 860736, Bug 862577, Bug 859771, Bug 859769, Bug 860734, Bug 862572, Bug 862574, Bug 862573.
In Mitre's CVE dictionary: CVE-2017-7606, CVE-2017-7619, CVE-2017-7941, CVE-2017-7943, CVE-2017-8343, CVE-2017-8344, CVE-2017-8345, CVE-2017-8346, CVE-2017-8347, CVE-2017-8348, CVE-2017-8349, CVE-2017-8350, CVE-2017-8351, CVE-2017-8352, CVE-2017-8353, CVE-2017-8354, CVE-2017-8355, CVE-2017-8356, CVE-2017-8357, CVE-2017-8765, CVE-2017-8830, CVE-2017-9098, CVE-2017-9141, CVE-2017-9142, CVE-2017-9143, CVE-2017-9144.
More information:

This update fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed RLE, ART, JNG, DDS, BMP, ICO, EPT, SUN, MTV, PICT, XWD, PCD, SFW, MAT, EXR, DCM, MNG, PCX or SVG files are processed.

For the stable distribution (jessie), these problems have been fixed in version 8:6.8.9.9-5+deb8u9.

For the upcoming stable distribution (stretch), these problems have been fixed in version 8:6.9.7.4+dfsg-8.

For the unstable distribution (sid), these problems have been fixed in version 8:6.9.7.4+dfsg-8.

We recommend that you upgrade your imagemagick packages.