Debian 10267 Published by

An imagemagick security update has been released for Debian GNU/Linux 9 to address multiple vulnerabilities in Imagemagick.



DSA 4715-1: imagemagick security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-4715-1 security@debian.org
  https://www.debian.org/security/ Moritz Muehlenhoff
July 02, 2020   https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : imagemagick
CVE ID : CVE-2019-13300 CVE-2019-13304 CVE-2019-13306 CVE-2019-13307
CVE-2019-15140 CVE-2019-19948

This update fixes multiple vulnerabilities in Imagemagick: Various memory
handling problems and cases of missing or incomplete input sanitising
may result in denial of service, memory disclosure or potentially the
execution of arbitrary code if malformed image files are processed.

For the oldstable distribution (stretch), these problems have been fixed
in version 8:6.9.7.4+dfsg-11+deb9u8.

We recommend that you upgrade your imagemagick packages.

For the detailed security status of imagemagick please refer to
its security tracker page at:
  https://security-tracker.debian.org/tracker/imagemagick

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at:   https://www.debian.org/security/