|
|
Log in / Subscribe / Register

Debian alert DSA-6169-1 (imagemagick)

From:  Moritz Muehlenhoff <jmm@debian.org>
To:  debian-security-announce@lists.debian.org
Subject:  [SECURITY] [DSA 6169-1] imagemagick security update
Date:  Thu, 19 Mar 2026 21:46:45 +0000
Message-ID:  <abxuxZsfsbtGfHxv@seger.debian.org>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6169-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff March 19, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : imagemagick CVE ID : CVE-2026-28493 CVE-2026-28494 CVE-2026-28686 CVE-2026-28687 CVE-2026-28688 CVE-2026-28689 CVE-2026-28690 CVE-2026-28691 CVE-2026-28692 CVE-2026-28693 CVE-2026-30883 CVE-2026-30929 CVE-2026-30931 CVE-2026-30935 CVE-2026-30936 CVE-2026-30937 CVE-2026-31853 CVE-2026-32259 Multiple security vulnerabilities were discovered in imagemagick, a software suite used for editing and manipulating digital images, which could lead to symlink races, information leaks, denial of service and potentially arbitrary code execution. For the stable distribution (trixie), these problems have been fixed in version 8:7.1.1.43+dfsg1-1+deb13u7. We recommend that you upgrade your imagemagick packages. For the detailed security status of imagemagick please refer to its security tracker page at: https://security-tracker.debian.org/tracker/imagemagick Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmm8bnYACgkQEMKTtsN8 TjZc+xAAmyjYFijF0LTQbirsjj0wbNZtEk0JYxfPae6YfnhG96L8QF6URRUfkKP/ iVR6+RIkjIX/4YARGLmXTlP8FQWceFHJ37nDnxbTREymifsmrUfI5/Ohi86Cl2N1 GdNrCRfnA5W3mKfDdp7bOd34o9M0V6b9pOjjGKu4c+dj3QvhusZs4CBQVrLrx6kN A7dVRiFeodRmjQQ+PQC6vo9giw3CM3KKfFfTPoHk763YIzLCVjpP66AzPUlb/cFc kpLNzdVy9QJPz2e/nYJpQrv/WVlnJn4QTrhYUDlfCcM6U22CzMIpo3ZA99GMMWTw RHocN3YAqWeB6rN1+V9ORRUg26Qspxxxnlo4XvXkM8uVAx24Jki2AwyOylChOb4s Ibg5i/rRUwM7/4PS/EvoBH6i0Uj5VoFR5xN2LWYu29GLiNKDZkuU7PPyVmC0wvRt 6Ci3Huw0asg3wPtPBRMzkupzjm/MdkrZaNik4DuAIJvMkyhkggBn6uzuHcdsLN/e EX6IRgbOPLXnP8s8LoW4VQhXzortXfZ0tyVilMLjeOJxlXdn3JzbQjb6+/cnVqJ9 GndoBXZPeY3xlLiTb9mdaXLFjH0EIfdfOaFJWH/QLI6cqeoolDuSK/yvAZ0fE3Qa so6LOqgyt5KdO1MFHcZf/245E4p+Dxb4d1SewMmtPFHtmkJMOAY= =2RFB -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds