Debian alert DLA-3429-1 (imagemagick)
| From: | Bastien Roucaries <rouca@debian.org> | |
| To: | <debian-lts-announce@lists.debian.org> | |
| Subject: | [SECURITY] [DLA 3429-1] imagemagick security update | |
| Date: | Sun, 21 May 2023 22:21:07 +0000 | |
| Message-ID: | <603be774062204c1d0e34e165784233b.rouca@debian.org> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3429-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Bastien Roucaries May 21, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : imagemagick Version : 8:6.9.10.23+dfsg-2.1+deb10u5 CVE ID : CVE-2021-20176 CVE-2021-20241 CVE-2021-20243 CVE-2021-20244 CVE-2021-20245 CVE-2021-20246 CVE-2021-20309 CVE-2021-20312 CVE-2021-20313 CVE-2021-39212 CVE-2022-28463 CVE-2022-32545 CVE-2022-32546 CVE-2022-32547 Debian Bug : 996588 1013282 1016442 Multiple vulnerabilities were fixed in imagemagick, a software suite, used for editing and manipulating digital images. CVE-2021-20176 A divide by zero was found in gem.c file. CVE-2021-20241 A divide by zero was found in jp2 coder. CVE-2021-20243 A divide by zero was found in dcm coder. CVE-2021-20244 A divide by zero was found in fx.c. CVE-2021-20245 A divide by zero was found in webp coder. CVE-2021-20246 A divide by zero was found in resample.c. CVE-2021-20309 A divide by zero was found in WaveImage.c CVE-2021-20312 An integer overflow was found in WriteTHUMBNAILImage() of coders/thumbnail.c CVE-2021-20313 A potential cipher leak was found when the calculate signatures in TransformSignature(). CVE-2021-39212 A policy bypass was found for postscript files. CVE-2022-28463 A bufer overflow was found in buffer overflow in cin coder. CVE-2022-32545 A undefined behavior (conversion outside the range of representable values of type 'unsigned char') was found in psd file handling. CVE-2022-32546 A undefined behavior (conversion outside the range of representable values of type 'long') was found in pcl file handling. CVE-2022-32547 An unaligned access was found in property.c For Debian 10 buster, these problems have been fixed in version 8:6.9.10.23+dfsg-2.1+deb10u5. We recommend that you upgrade your imagemagick packages. For the detailed security status of imagemagick please refer to its security tracker page at: https://security-tracker.debian.org/tracker/imagemagick Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmRqmVMACgkQADoaLapB CF8kRg/7BM6uzmf+carUUMDzTBep32H0bkjAc4rSKaLT6CW5q9AGplSijEGsL+2n sWK3Y3x8pPaaTXIOV+Xx0vDTl9isxF4r6cyckp+Pziz8bSPTd50r0IgzKZP0k57r YH/Z5VpP59BWAsNCIiaybi65+avf/00kw2CWZ08feC1vV2LmQUp5wDmwA3z/8E9P PiZ2gVOoc1aTKzUgGkGJPoiCeaAJl8cvSwUH4txXPDTbtv0gjFVVxfLmB7nnWc5b QWTo4MOoowRORdGPtFIjgkozdDMA1toHK/8fPB2ke/N0lBXjivFwsUiqMb1jAgjt OkVzqfwk/Plm2KvwGLAjn6dTH2dvAueNovX1jcbIdEeWZuIqooydaLdEgE8/OLBm GlvIN+hIZkWBW7F0Wa0WuVj2sgdO3dBdlKi2dqmq9qBMcc4IxLJiP0sRxaegf/JN Sg8SU288p2C9uBR6AqPXCqFIGl8MqoB9nTqpebHSpzXFGJTb52NQArV/1zjDZGXR voMkPrZuRd0sp7jxpKT5dQbhxT+zCL7XpeiMCUCCh0mAeTT4SMQTyJVtlcgLCibx fWtFYu9L3yZUjnXTBmI7Bfvn/EMwhilYH7NtF0jyves7erMFBifaKN2riosW7jTL aZovpK9R+i0r3PJA9UUhZZYM161jafMRQ6bwBPOgGDL/2K+ZxlY= =eYBc -----END PGP SIGNATURE-----
