DSA-4032-1 imagemagick -- security update

Related Vulnerabilities: CVE-2017-12983   CVE-2017-13134   CVE-2017-13758   CVE-2017-13769   CVE-2017-14224   CVE-2017-14607   CVE-2017-14682   CVE-2017-14989   CVE-2017-15277  

This update fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed GIF, TTF, SVG, TIFF, PCX, JPG or SFW files are processed. For the stable distribution (stretch), these problems have been fixed in version 8:6.9.7.4+dfsg-11+deb9u3. We recommend that you upgrade your imagemagick packages.

Debian Security Advisory

DSA-4032-1 imagemagick -- security update

Date Reported:
12 Nov 2017
Affected Packages:
imagemagick
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 873134, Bug 873099, Bug 878508, Bug 878507, Bug 876097, Bug 878527, Bug 876488, Bug 878562.
In Mitre's CVE dictionary: CVE-2017-12983, CVE-2017-13134, CVE-2017-13758, CVE-2017-13769, CVE-2017-14224, CVE-2017-14607, CVE-2017-14682, CVE-2017-14989, CVE-2017-15277.
More information:

This update fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed GIF, TTF, SVG, TIFF, PCX, JPG or SFW files are processed.

For the stable distribution (stretch), these problems have been fixed in version 8:6.9.7.4+dfsg-11+deb9u3.

We recommend that you upgrade your imagemagick packages.