[Git][security-tracker-team/security-tracker][master] Imagemagick triagging

Bastien Roucariès (@rouca) rouca at debian.org
Sun Jul 12 09:37:36 BST 2026



Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker


Commits:
eccf755a by Bastien Roucariès at 2026-07-12T10:37:09+02:00
Imagemagick triagging

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -18140,6 +18140,8 @@ CVE-2026-36849 [Denial of Service via large SamplesPerPixel tag]
 CVE-2026-XXXX [default policy.xml HTTP/HTTPS/URL delegate rules are no-ops]
 	- imagemagick 8:7.1.2.25+dfsg1-2 (bug #1140176)
 	[trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u10
+	[bookworm] - imagemagick 8:6.9.11.60+dfsg-1.6+deb12u11
+	[bullseye] - imagemagick 8:6.9.11.60+dfsg-1.3+deb11u14
 CVE-2026-9507 (A session fixation vulnerability has been identified in osTicket v1.18 ...)
 	- osticket <itp> (bug #998157)
 CVE-2026-9307 (A sensitive information disclosure security issue exists within the af ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eccf755a16026d6f5159634997bf427bea6d6ee7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eccf755a16026d6f5159634997bf427bea6d6ee7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260712/b53db57c/attachment.htm>


More information about the debian-security-tracker-commits mailing list