UbuntuUpdates.org

Package "imagemagick"

Name: imagemagick

Description:

image manipulation programs -- binaries

Latest version: 8:6.9.10.23+dfsg-2.1ubuntu11.9
Release: focal (20.04)
Level: updates
Repository: universe
Homepage: https://www.imagemagick.org/

Links


Download "imagemagick"


Other versions of "imagemagick" in Focal

Repository Area Version
base universe 8:6.9.10.23+dfsg-2.1ubuntu11
security universe 8:6.9.10.23+dfsg-2.1ubuntu11.9

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 8:6.9.10.23+dfsg-2.1ubuntu11.2 2020-12-15 20:06:47 UTC

  imagemagick (8:6.9.10.23+dfsg-2.1ubuntu11.2) focal-security; urgency=medium

  * SECURITY UPDATE: division by zero
    - debian/patches/CVE-2020-27560.patch: Change division to multiplication in
      OptimizeLayerFrames in magick/layer.c
    - CVE-2020-27560

 -- Avital Ostromich <email address hidden> Wed, 18 Nov 2020 08:52:45 -0500

Source diff to previous version
CVE-2020-27560 ImageMagick 7.0.10-34 allows Division by Zero in OptimizeLayerFrames in MagickCore/layer.c, which may cause a denial of service.

Version: 8:6.9.10.23+dfsg-2.1ubuntu11.1 2020-09-28 14:06:56 UTC

  imagemagick (8:6.9.10.23+dfsg-2.1ubuntu11.1) focal-security; urgency=medium

  * Merge Security patches from Debian.
  * SECURITY UPDATE: Heap-based buffer overflow.
    - debian/patches/CVE-2019-19948.patch: Fix heap-based buffer overflow
      in coders/sgi.c.
    - debian/patches/CVE-2019-19949.patch: Fix heap-based buffer overflow
      in coders/png.c.
    - CVE-2019-19948
    - CVE-2019-19949

 -- Eduardo Barretto <email address hidden> Wed, 23 Sep 2020 16:17:40 -0300

CVE-2019-19948 In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c.
CVE-2019-19949 In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_pr



About   -   Send Feedback to @ubuntu_updates