[Git][security-tracker-team/security-tracker][master] imagemagick/LTS

Bastien Roucariès (@rouca) rouca at debian.org
Wed Aug 5 09:26:28 BST 2026



Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker


Commits:
dd02e904 by Bastien Roucariès at 2026-08-05T10:25:39+02:00
imagemagick/LTS

Postpone a few issue:
- DoS only
- Need particular flags

May be fixed with later release

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3171,6 +3171,8 @@ CVE-2026-65975 (Pydantic AI is a Python agent framework for building application
 	NOT-FOR-US: Pydantic AI
 CVE-2026-64685 (ImageMagick is free and open-source software used for editing and mani ...)
 	- imagemagick 8:7.1.2.27+dfsg1-1
+	[bookworm] - imagemagick <postponed> (minor issue)
+	[bullseye] - imagemagick <postponed> (minor issue)
 	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7rgw-xg25-prjm
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/093f476e985d61557ea75ad0ef30d491dff816f3 (7.1.2-27)
 CVE-2026-64635 (Improper handling of the returnUrl parameter in the Forgot Password fu ...)
@@ -3181,16 +3183,22 @@ CVE-2026-63118 (MCP Ruby SDK is the official Ruby SDK for Model Context Protocol
 	NOT-FOR-US: MCP Ruby SDK
 CVE-2026-62946 (ImageMagick is free and open-source software used for editing and mani ...)
 	- imagemagick 8:7.1.2.27+dfsg1-1
+	[bookworm] - imagemagick <postponed> (minor issue)
+	[bullseye] - imagemagick <postponed> (minor issue)
 	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h22j-f9xw-xjjm
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/538ad18f3a421d1dd9629baa747eebc137c32b67 (7.1.2-27)
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/8018a5c3214ca9bf11a86c2816833dee920b1340 (6.9.13-52)
 CVE-2026-62363 (ImageMagick is free and open-source software used for editing and mani ...)
 	- imagemagick 8:7.1.2.27+dfsg1-1
+	[bookworm] - imagemagick <postponed> (minor issue)
+	[bullseye] - imagemagick <postponed> (minor issue)
 	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-422r-8c97-xcg4
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/be99ffaa57c8f91ed8897c2221ff0940c561a368 (7.1.2-27)
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/0bbf7e48f5dd0ef540d3ae1ae8dfc6cd036fb640 (7.1.2-27)
 CVE-2026-62343 (ImageMagick is free and open-source software used for editing and mani ...)
 	- imagemagick 8:7.1.2.26+dfsg1-1
+	[bookworm] - imagemagick <postponed> (minor issue)
+	[bullseye] - imagemagick <postponed> (minor issue)
 	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-f5m7-cqgw-8hm7
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/9acf93f66b0f8495fa222e1a27c3db534cd78864 (7.1.2-26)
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/b3a93f501011a8882ec4962dd6db9f0a71e6f050 (6.9.13-51)
@@ -7257,6 +7265,8 @@ CVE-2026-66012 (SiYuan before v3.7.2 contains a missing authorization vulnerabil
 	NOT-FOR-US: SiYuan
 CVE-2026-66011 (ImageMagick before 7.1.2-27 contains a memory leak vulnerability in th ...)
 	- imagemagick 8:7.1.2.27+dfsg1-1
+	[bookworm] - imagemagick <postponed> (minor issue)
+	[bullseye] - imagemagick <postponed> (minor issue)
 	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cvhv-g4rq-3hmw
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/e3e69118c29064e2716ca89aab635ea95a15dd49 (7.1.2-27)
 CVE-2026-16766 (Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dd02e9043cdd31e7d4a72add7f3cf0a6f0e47f4c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dd02e9043cdd31e7d4a72add7f3cf0a6f0e47f4c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/7a39411e/attachment.htm>


More information about the debian-security-tracker-commits mailing list