[ubuntu/mantic-proposed] imagemagick 8:6.9.11.60+dfsg-1.6ubuntu1 (Accepted)

Nishit Majithia nishit.majithia at canonical.com
Tue Jul 4 12:44:17 UTC 2023


imagemagick (8:6.9.11.60+dfsg-1.6ubuntu1) mantic; urgency=medium

  * SECURITY UPDATE: heap-based buffer overflow issue
    - debian/patches/CVE-2021-3610.patch: eliminate heap buffer overflow
      vulnerability
    - debian/patches/CVE-2023-3428.patch: fix heap buffer overflow
    - CVE-2021-3610
    - CVE-2023-3428
  * SECURITY UPDATE: DoS while processing crafted SVG files
    - debian/patches/CVE-2023-1289*.patch: erecursion detection
    - CVE-2023-1289
  * SECURITY UPDATE: out-of-bound read issue
    - debian/patches/CVE-2023-1906.patch: fix possible heap buffer overflow
    - CVE-2023-1906
  * SECURITY UPDATE: stack-based buffer overflow issue
    - debian/patches/CVE-2023-3195.patch: fix stack overflow when parsing
      malicious tiff image
    - CVE-2023-3195
  * SECURITY UPDATE: integer overflow vulnerability
    - debian/patches/CVE-2023-34151*.patch: properly cast double to size_t
    - CVE-2023-34151

Date: Mon, 03 Jul 2023 14:53:27 +0530
Changed-By: Nishit Majithia <nishit.majithia at canonical.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Signed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.11.60+dfsg-1.6ubuntu1
-------------- next part --------------
Format: 1.8
Date: Mon, 03 Jul 2023 14:53:27 +0530
Source: imagemagick
Built-For-Profiles: noudeb
Architecture: source
Version: 8:6.9.11.60+dfsg-1.6ubuntu1
Distribution: mantic
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Nishit Majithia <nishit.majithia at canonical.com>
Changes:
 imagemagick (8:6.9.11.60+dfsg-1.6ubuntu1) mantic; urgency=medium
 .
   * SECURITY UPDATE: heap-based buffer overflow issue
     - debian/patches/CVE-2021-3610.patch: eliminate heap buffer overflow
       vulnerability
     - debian/patches/CVE-2023-3428.patch: fix heap buffer overflow
     - CVE-2021-3610
     - CVE-2023-3428
   * SECURITY UPDATE: DoS while processing crafted SVG files
     - debian/patches/CVE-2023-1289*.patch: erecursion detection
     - CVE-2023-1289
   * SECURITY UPDATE: out-of-bound read issue
     - debian/patches/CVE-2023-1906.patch: fix possible heap buffer overflow
     - CVE-2023-1906
   * SECURITY UPDATE: stack-based buffer overflow issue
     - debian/patches/CVE-2023-3195.patch: fix stack overflow when parsing
       malicious tiff image
     - CVE-2023-3195
   * SECURITY UPDATE: integer overflow vulnerability
     - debian/patches/CVE-2023-34151*.patch: properly cast double to size_t
     - CVE-2023-34151
Checksums-Sha1:
 fd3422ed94f3ac8e4d649e282b4b8d63622d7d41 5181 imagemagick_6.9.11.60+dfsg-1.6ubuntu1.dsc
 f71bcb154719f79fd9e0ea815ef60fe543a77f3c 259460 imagemagick_6.9.11.60+dfsg-1.6ubuntu1.debian.tar.xz
 d764768f514ede711e6bfbf4e2a6ca1bec20416c 17732 imagemagick_6.9.11.60+dfsg-1.6ubuntu1_source.buildinfo
Checksums-Sha256:
 6b6684597220469af497f7c0f6d60953244cec6d80006a3c5675a5082db79d44 5181 imagemagick_6.9.11.60+dfsg-1.6ubuntu1.dsc
 bfd162e4e6c44968942b1ff4574241ef92aee14d5ad6f18706f4cf6ff550d02b 259460 imagemagick_6.9.11.60+dfsg-1.6ubuntu1.debian.tar.xz
 39af3af210839f1977e150c078dc657013fd9ee3f807e49db3133e7c66baff22 17732 imagemagick_6.9.11.60+dfsg-1.6ubuntu1_source.buildinfo
Files:
 00a56b16b9961980cd19826176e76c5c 5181 graphics optional imagemagick_6.9.11.60+dfsg-1.6ubuntu1.dsc
 48f5345d34c70acbc08343b4393a0425 259460 graphics optional imagemagick_6.9.11.60+dfsg-1.6ubuntu1.debian.tar.xz
 a3be98750aafc5d2dda6af39cce8e589 17732 graphics optional imagemagick_6.9.11.60+dfsg-1.6ubuntu1_source.buildinfo
Original-Maintainer: ImageMagick Packaging Team <pkg-gmagick-im-team at lists.alioth.debian.org>


More information about the mantic-changes mailing list