UbuntuUpdates.org

Package "imagemagick"

Name: imagemagick

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • image manipulation programs -- infrastructure
  • object-oriented C++ interface to ImageMagick - header files
  • C++ interface to ImageMagick -- quantum depth Q16
  • C++ interface to ImageMagick - development files (Q16)

Latest version: 8:6.9.10.14+dfsg-7ubuntu2.2
Release: disco (19.04)
Level: security
Repository: main

Links

Save this URL for the latest version of "imagemagick": https://www.ubuntuupdates.org/imagemagick



Other versions of "imagemagick" in Disco

Repository Area Version
base universe 8:6.9.10.14+dfsg-7ubuntu2
base main 8:6.9.10.14+dfsg-7ubuntu2
security universe 8:6.9.10.14+dfsg-7ubuntu2.2
updates main 8:6.9.10.14+dfsg-7ubuntu2.2
updates universe 8:6.9.10.14+dfsg-7ubuntu2.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 8:6.9.10.14+dfsg-7ubuntu2.2 2019-06-25 13:08:01 UTC

  imagemagick (8:6.9.10.14+dfsg-7ubuntu2.2) disco-security; urgency=medium

  * SECURITY UPDATE: multiple security issues
    - debian/patches/CVE-*.patch: backport multiple upstream commits.
    - CVE-2018-20467, CVE-2019-7175, CVE-2019-7395, CVE-2019-7396,
      CVE-2019-7397, CVE-2019-7398, CVE-2019-9956, CVE-2019-10649,
      CVE-2019-10650, CVE-2019-11470, CVE-2019-11472, CVE-2019-11597,
      CVE-2019-11598
  * SECURITY UPDATE: code execution vulnerabilities in ghostscript as
    invoked by imagemagick
    - debian/patches/200-disable-ghostscript-formats.patch: disable
      ghostscript handled types by default in policy.xml
    - debian/tests/rose-*: remove pdf tests.

 -- Marc Deslauriers <email address hidden> Thu, 20 Jun 2019 13:35:10 -0400

CVE-2018-20467 In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote a
CVE-2019-7175 In ImageMagick before 7.0.8-25, some memory leaks exist in DecodeImage in coders/pcd.c.
CVE-2019-7395 In ImageMagick before 7.0.8-25, a memory leak exists in WritePSDChannel in coders/psd.c.
CVE-2019-7396 In ImageMagick before 7.0.8-25, a memory leak exists in ReadSIXELImage in coders/sixel.c.
CVE-2019-7397 In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in WritePDFImage in coders/pdf.c.
CVE-2019-7398 In ImageMagick before 7.0.8-25, a memory leak exists in WriteDIBImage in coders/dib.c.
CVE-2019-9956 In ImageMagick 7.0.8-35 Q16, there is a stack-based buffer overflow in the function PopHexPixel of coders/ps.c, which allows an attacker to cause a d
CVE-2019-10649 In ImageMagick 7.0.8-36 Q16, there is a memory leak in the function SVGKeyValuePairs of coders/svg.c, which allows an attacker to cause a denial of s
CVE-2019-10650 In ImageMagick 7.0.8-36 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to caus
CVE-2019-11470 The cineon parsing component in ImageMagick 7.0.8-26 Q16 allows attackers to cause a denial-of-service (uncontrolled resource consumption) by craftin
CVE-2019-11472 ReadXWDImage in coders/xwd.c in the XWD image parsing component of ImageMagick 7.0.8-41 Q16 allows attackers to cause a denial-of-service (divide-by-
CVE-2019-11597 In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to caus
CVE-2019-11598 In ImageMagick 7.0.8-40 Q16, there is a heap-based buffer over-read in the function WritePNMImage of coders/pnm.c, which allows an attacker to cause



About   -   Send Feedback to @ubuntu_updates