[Git][security-tracker-team/security-tracker][master] Add more imagemagick issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Jul 1 08:56:54 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a44b2404 by Salvatore Bonaccorso at 2026-07-01T09:56:33+02:00
Add more imagemagick issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -73,13 +73,23 @@ CVE-2026-56399 (Open WebUI before 0.6.27 contains a server-side request forgery
 CVE-2026-56377 (ImageMagick before 7.1.2-24 contains an incorrect policy check that al ...)
 	TODO: check
 CVE-2026-56369 (ImageMagick before 7.1.2-22 contains an information disclosure vulnera ...)
-	TODO: check
+	- imagemagick 8:7.1.2.23+dfsg1-1
+	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qv2q-c278-pch5
+	TODO: check fixing commit in 7.1.2-22
 CVE-2026-56365 (ImageMagick before 7.1.2-19 contains a memory leak vulnerability in th ...)
-	TODO: check
+	- imagemagick 8:7.1.2.19+dfsg1-1
+	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-x928-4434-crqj
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/ca761f220bbf0470e2e7967639bcfb5be305ad28 (7.1.2-19)
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/28ed1c9993fe437a44c00bee2ee20d58f7e0204c (6.9.13-44)
 CVE-2026-56364 (ImageMagick before 7.1.2-13 contains a memory leak vulnerability in Lo ...)
-	TODO: check
+	- imagemagick 8:7.1.2.13+dfsg1-1
+	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qp59-x883-77qv
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/a52c1b402be08ef8ae193f28ac5b2e120f2fa26f (7.1.2-13)
 CVE-2026-56363 (ImageMagick before 7.1.2-22 contains a division by zero vulnerability  ...)
-	TODO: check
+	- imagemagick 8:7.1.2.23+dfsg1-1
+	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vf33-6r7x-66xx
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/d67eef71764cfeca07b4edf8a8ae922180f5f2e4 (7.1.2-22)
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/7a48e0b3107608c7d87a172473cfd5294bc9e81f (6.9.13-47)
 CVE-2026-56361 (ImageMagick before 7.1.2-19 contains an off-by-one error in morphology ...)
 	- imagemagick 8:7.1.2.19+dfsg1-1
 	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-q8h3-jv9v-57qx



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a44b2404b5a924c9a1e6b098bc2ca88978e42610

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a44b2404b5a924c9a1e6b098bc2ca88978e42610
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260701/f82e03b7/attachment.htm>


More information about the debian-security-tracker-commits mailing list