Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 4715-1] imagemagick security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 4715-1] imagemagick security update


Chronologisch Thread 
  • From: Moritz Muehlenhoff <jmm AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 4715-1] imagemagick security update
  • Date: Thu, 2 Jul 2020 18:34:51 +0000
  • List-archive: https://lists.debian.org/msgid-search/20200702183451.GA25804 AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From: Date:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=br+P129snC5Fgsx1gkBtPgBVywVrwYnS5OZkOMfqaQc=; b=SE F5FwrfgCeTnqjfcNOoKKsDMaRyEZGsQ4f9n+Kw3SwBla0u/zrM/fe3AUYytuKkNXrhYK4FwDhjBNd BnwMpnyT4en6CmsWLoEqWJqNBGMlj7PKRaYFkMOynSmu8CzQdfxr7C+/WqdKYbfFsdOfkeI5G4eKW r2KTaVvkZYVt/CJv4j3YIl4kDnhhBZsdEZHGRuXis5bYkPRsh9dCECdueyeupK/3gQfMIdM1MAYoH yTeaZDmVY7A7guda7ZCKC2sDEVVHJ+rs7zhTDwlpy03QgWSc2XkW5kwWtrIkjhsggeMFwbAyDa4uL aoSymEQ9mMHe99OtRp3QW+jTxyo95YOg==;
  • Old-return-path: <jmm AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Thu, 2 Jul 2020 18:35:07 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <do2AZteL1JL.A.0t.bji_eB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4715-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
July 02, 2020 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : imagemagick
CVE ID : CVE-2019-13300 CVE-2019-13304 CVE-2019-13306 CVE-2019-13307
CVE-2019-15140 CVE-2019-19948

This update fixes multiple vulnerabilities in Imagemagick: Various memory
handling problems and cases of missing or incomplete input sanitising
may result in denial of service, memory disclosure or potentially the
execution of arbitrary code if malformed image files are processed.

For the oldstable distribution (stretch), these problems have been fixed
in version 8:6.9.7.4+dfsg-11+deb9u8.

We recommend that you upgrade your imagemagick packages.

For the detailed security status of imagemagick please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/imagemagick

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl7+KI0ACgkQEMKTtsN8
TjYf6BAAuE+XSVJzQMenV4PJvbbDAoMP1p23VpHP9W2i7yxf1zF+KC9ouNWlQDue
eX8cg2NqbN2mnvk7deCK3Ngxlx+oMYXl9eiCF2cjbdXeFoK8E4F/15slSn1bMb6z
C6hrrpqE1Omx0kefUhBSSQ2C+RLowvPJjpTqlnYe10GygRUMMpRVS+aO5HjLZQVb
8cLvlLiWUCRKU0nsosLh3cvFz/OsW7PJ+uU7SJJQkfrwJiKi00JjDW+LFYlag/CH
VAt4opWfN1gZW/sBxGbA77qB+r1MFyfBU3d9yi4mWRl7HyS34LFL87Xl8lKkj5sN
/g4afp92UQHB4G82JvFgqJcup+zvHUK8KNcQN76fowchaugoTxg8xZsuJB5zun1j
YKfFc1JJwwa3PBjFktz0iRJYE2PpvfccX2TdtyLPMSqIvfN3oifG2Wl/rsI6hLkn
vAnaGuDuFY6HqVytNmQ5vZ0nOEPMz2OX0H1fGZzcIQrL1fO0wmPldLZulGiPbVr4
s4o1o/UlL8fgepA4eGFwzQmhie3ZR9PtNPMcfKLDv1ZS7kZA6Q3pwj89fWKmV8Cc
GrdtByzLz//cBxhPNbdXYNr4KXEMCd1+fIY+etIEJ5z+PsFCJkG2nSbScjSdBJpq
3pDqW5w2mphOszZo5U3pe49r0wq0spoiTWOOqulgk9k0iWSU57w=
=fL5E
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 4715-1] imagemagick security update, Moritz Muehlenhoff, 02.07.2020

Archiv bereitgestellt durch MHonArc 2.6.19.

Seitenanfang