it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Moritz Muehlenhoff <jmm AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 5347-1] imagemagick security update
- Date: Mon, 13 Feb 2023 18:58:10 +0000
- Authentication-results: mail.piratenpartei.de; dkim=none; spf=none (mail.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 2001:41b8:202:deb:216:36ff:fe40:4002) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"; dmarc=none
- List-archive: https://lists.debian.org/msgid-search/Y+qIQtO8Zq7ySJF3 AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From:Date :Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=KhkbCZTHjwlIgKrFwqWpypcnN1DSCnyepLK6m2TsmS0=; b=sA r8vomBhKHxWSdJLBb7eSgPhtwAxx8aWNaIUA/JImluXjxV/Is4cSLNsNYFBzuB+5smt3bVXUjqzVQ bnzA7uCx5sCAITIV+jt52G5krVpyK+StUr7A7WfUF59kOejIlsfLJCbIVU0UQNIzP3k2H6GZXziAT gzKf0//renVOSY8w91F1tngzuTehjgS7sz5DVolWd9HslgO4XmOiPrbP3XONKS/hBxL2IaMxftZ5V 9ixMc4BMXde7fpv4ZDctI+yUzGIby8ZRJAJBQdmeo6ctwyy1psXYC7HXZJnS85E19/8eygM6ZCGvw uZhff1W1nkcgLPMeePBD7tz/tQ0jryiA==;
- Old-return-path: <jmm AT seger.debian.org>
- Priority: urgent
- Resent-date: Mon, 13 Feb 2023 18:58:33 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <JPFIThfjlsF.A.ymD.Zho6jB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-5347-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
February 13, 2023 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : imagemagick
CVE ID : CVE-2022-44267 CVE-2022-44268
Bryan Gonzalez discovered that the PNG support in Imagemagick could be
tricked into embedding the content of an arbitrary file when converting
an image file.
For the stable distribution (bullseye), these problems have been fixed in
version 8:6.9.11.60+dfsg-1.3+deb11u1.
We recommend that you upgrade your imagemagick packages.
For the detailed security status of imagemagick please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/imagemagick
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmPqhwAACgkQEMKTtsN8
TjbjNBAAgN2gK22qgX0E5KyhfdzBoSxOD92zPFUtnMjV45Z3by3zkyaXLQKxk5uY
keBnb1zNaOcvZv4vmcaCNln2UqYwHVM6qIGKSEQU73cD0JbuKfSigLk4QcORtXmE
sMWN1B8n4wutbNgldhIXch4n1zA4ty3TIDFcgwA+cS4qOOfta5Du7O23FSzcyWbQ
dPbrLx5hpRA6u/exqhjlDmkuXAoAfDxXBYwdyY9UWYRc3tT9Wx4lW7/glxz1r5FV
5L2qoaGLw1RXAaycZxtU/SP5+Ogt5qEbooCR3e1X6+pSWgwriqSogFJNjJoEHsLg
rzLFD68yBndGC+FYzeSv4bTuv6ycvR+14THobvEeT6M/o1MZH9F5oV47hv/htIQY
f7h0N8BL8ZWKBWPfavsRDmpxI2vuAIGKSTLJk+0K3fpzYZrtop4wMCKwE5zKZ4IQ
SSUi9/bwZfSTwQl8zkqI3/hwbjTx3qFFLMsbarpPICKabPwHqDVG7/fDBGQgGDYA
eSNil/yBNGx69lNaC2VeaHDIs/f28mCdZ/fXRs5Uc+iNbOhsqSLNsLbCvBjq69Uu
EhbBRUTGRlw7+rM5bA0yptH0Wh/0HLarGMhE0Zdw4Gvgd8FBO8P5rQTr4E/vLvy6
mNKGUCvWdQMKa75MFQhYDT2R/nCZr2Zzp0imrA9VgZ0+t+dBu3A=
=sXAd
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 5347-1] imagemagick security update, Moritz Muehlenhoff, 13.02.2023
Archiv bereitgestellt durch MHonArc 2.6.24.