-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4715-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff July 02, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : imagemagick CVE ID : CVE-2019-13300 CVE-2019-13304 CVE-2019-13306 CVE-2019-13307 CVE-2019-15140 CVE-2019-19948 This update fixes multiple vulnerabilities in Imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or potentially the execution of arbitrary code if malformed image files are processed. For the oldstable distribution (stretch), these problems have been fixed in version 8:6.9.7.4+dfsg-11+deb9u8. We recommend that you upgrade your imagemagick packages. For the detailed security status of imagemagick please refer to its security tracker page at: https://security-tracker.debian.org/tracker/imagemagick Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl7+KI0ACgkQEMKTtsN8 TjYf6BAAuE+XSVJzQMenV4PJvbbDAoMP1p23VpHP9W2i7yxf1zF+KC9ouNWlQDue eX8cg2NqbN2mnvk7deCK3Ngxlx+oMYXl9eiCF2cjbdXeFoK8E4F/15slSn1bMb6z C6hrrpqE1Omx0kefUhBSSQ2C+RLowvPJjpTqlnYe10GygRUMMpRVS+aO5HjLZQVb 8cLvlLiWUCRKU0nsosLh3cvFz/OsW7PJ+uU7SJJQkfrwJiKi00JjDW+LFYlag/CH VAt4opWfN1gZW/sBxGbA77qB+r1MFyfBU3d9yi4mWRl7HyS34LFL87Xl8lKkj5sN /g4afp92UQHB4G82JvFgqJcup+zvHUK8KNcQN76fowchaugoTxg8xZsuJB5zun1j YKfFc1JJwwa3PBjFktz0iRJYE2PpvfccX2TdtyLPMSqIvfN3oifG2Wl/rsI6hLkn vAnaGuDuFY6HqVytNmQ5vZ0nOEPMz2OX0H1fGZzcIQrL1fO0wmPldLZulGiPbVr4 s4o1o/UlL8fgepA4eGFwzQmhie3ZR9PtNPMcfKLDv1ZS7kZA6Q3pwj89fWKmV8Cc GrdtByzLz//cBxhPNbdXYNr4KXEMCd1+fIY+etIEJ5z+PsFCJkG2nSbScjSdBJpq 3pDqW5w2mphOszZo5U3pe49r0wq0spoiTWOOqulgk9k0iWSU57w= =fL5E -----END PGP SIGNATURE-----