DLA-3429-1

Source
https://storage.googleapis.com/debian-osv/dla-osv/DLA-3429-1.json
Aliases
Published
2023-05-21T00:00:00Z
Modified
2023-05-21T23:17:57.347113Z
Details

Multiple vulnerabilities were fixed in imagemagick, a software suite, used for editing and manipulating digital images.

  • CVE-2021-20176 A divide by zero was found in gem.c file.
  • CVE-2021-20241 A divide by zero was found in jp2 coder.
  • CVE-2021-20243 A divide by zero was found in dcm coder.
  • CVE-2021-20244 A divide by zero was found in fx.c.
  • CVE-2021-20245 A divide by zero was found in webp coder.
  • CVE-2021-20246 A divide by zero was found in resample.c.
  • CVE-2021-20309 A divide by zero was found in WaveImage.c
  • CVE-2021-20312 An integer overflow was found in WriteTHUMBNAILImage() of coders/thumbnail.c
  • CVE-2021-20313 A potential cipher leak was found when the calculate signatures in TransformSignature().
  • CVE-2021-39212 A policy bypass was found for postscript files.
  • CVE-2022-28463 A bufer overflow was found in buffer overflow in cin coder.
  • CVE-2022-32545 A undefined behavior (conversion outside the range of representable values of type unsigned char) was found in psd file handling.
  • CVE-2022-32546 A undefined behavior (conversion outside the range of representable values of type long) was found in pcl file handling.
  • CVE-2022-32547 An unaligned access was found in property.c

For Debian 10 buster, these problems have been fixed in version 8:6.9.10.23+dfsg-2.1+deb10u5.

We recommend that you upgrade your imagemagick packages.

For the detailed security status of imagemagick please refer to its security tracker page at: https://security-tracker.debian.org/tracker/imagemagick

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS

References

Affected packages

Debian:10 / imagemagick

imagemagick

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0
Fixed
8:6.9.10.23+dfsg-2.1+deb10u5

Affected versions

8:6.*

8:6.9.10.23+dfsg-2.1
8:6.9.10.23+dfsg-2.1+deb10u1
8:6.9.10.23+dfsg-2.1+deb10u2
8:6.9.10.23+dfsg-2.1+deb10u3
8:6.9.10.23+dfsg-2.1+deb10u4