DSA-3914-1 imagemagick -- security update

Related Vulnerabilities: CVE-2017-9439   CVE-2017-9440   CVE-2017-9501   CVE-2017-10928   CVE-2017-11141   CVE-2017-11170   CVE-2017-11188   CVE-2017-11360   CVE-2017-11352   CVE-2017-11449   CVE-2017-11448   CVE-2017-11447   CVE-2017-11450   CVE-2017-11478  

This updates fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed RLE, SVG, PSD, PDB, DPX, MAT, TGA, VST, CIN, DIB, MPC, EPT, JNG, DJVU, JPEG, ICO, PALM or MNG files are processed. For the oldstable distribution (jessie), these problems have been fixed in version 8:6.8.9.9-5+deb8u10. For the stable distribution (stretch), these problems have been fixed in version 8:6.9.7.4+dfsg-11+deb9u1. For the unstable distribution (sid), these problems have been fixed in version 8:6.9.7.4+dfsg-12. We recommend that you upgrade your imagemagick packages.

Debian Security Advisory

DSA-3914-1 imagemagick -- security update

Date Reported:
18 Jul 2017
Affected Packages:
imagemagick
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 863126, Bug 867367, Bug 867778, Bug 867721, Bug 864273, Bug 864274, Bug 867806, Bug 868264.
In Mitre's CVE dictionary: CVE-2017-9439, CVE-2017-9440, CVE-2017-9501, CVE-2017-10928, CVE-2017-11141, CVE-2017-11170, CVE-2017-11188, CVE-2017-11360, CVE-2017-11352, CVE-2017-11449, CVE-2017-11448, CVE-2017-11447, CVE-2017-11450, CVE-2017-11478.
More information:

This updates fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed RLE, SVG, PSD, PDB, DPX, MAT, TGA, VST, CIN, DIB, MPC, EPT, JNG, DJVU, JPEG, ICO, PALM or MNG files are processed.

For the oldstable distribution (jessie), these problems have been fixed in version 8:6.8.9.9-5+deb8u10.

For the stable distribution (stretch), these problems have been fixed in version 8:6.9.7.4+dfsg-11+deb9u1.

For the unstable distribution (sid), these problems have been fixed in version 8:6.9.7.4+dfsg-12.

We recommend that you upgrade your imagemagick packages.