[Git][security-tracker-team/security-tracker][master] Add more imagemagick issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Mar 10 16:00:51 GMT 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4e14c981 by Salvatore Bonaccorso at 2026-03-10T17:00:19+01:00
Add more imagemagick issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -105,7 +105,9 @@ CVE-2026-30887 (OneUptime is a solution for monitoring and managing online servi
CVE-2026-30885 (WWBN AVideo is an open source video platform. Prior to 25.0, the /obje ...)
NOT-FOR-US: WWBN AVideo
CVE-2026-30883 (ImageMagick is free and open-source software used for editing and mani ...)
- TODO: check
+ - imagemagick <unfixed>
+ NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qmw5-2p58-xvrc
+ NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/5897fb65d173a57729026321d5067c9ddca5c56f (7.1.2-16)
CVE-2026-30870 (PowerSync Service is the server-side component of the PowerSync sync e ...)
NOT-FOR-US: PowerSync Service
CVE-2026-30869 (SiYuan is a personal knowledge management system. Prior to 3.5.10, a p ...)
@@ -119,19 +121,37 @@ CVE-2026-2364 (If a legitimate user confirms a self-update prompt or initiate an
CVE-2026-29773 (Kubewarden is a policy engine for Kubernetes. Kubewarden cluster opera ...)
NOT-FOR-US: Kubewarden
CVE-2026-28693 (ImageMagick is free and open-source software used for editing and mani ...)
- TODO: check
+ - imagemagick <unfixed>
+ NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hffp-q43q-qq76
CVE-2026-28692 (ImageMagick is free and open-source software used for editing and mani ...)
- TODO: check
+ - imagemagick <unfixed>
+ NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-mrmj-x24c-wwcv
+ NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/cb6cc0611baa4dac59add6439fa1d8af33fc5927 (7.1.2-16)
CVE-2026-28691 (ImageMagick is free and open-source software used for editing and mani ...)
- TODO: check
+ - imagemagick <unfixed>
+ NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wj8w-pjxf-9g4f
+ NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/87f619bcd066a3c8e8fae4addb99f15d496ae881 (7.1.2-16)
CVE-2026-28690 (ImageMagick is free and open-source software used for editing and mani ...)
- TODO: check
+ - imagemagick <unfixed>
+ NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7h7q-j33q-hvpf
+ NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/e6e874875e48dd9838acca3bd22c14a4d2f1b3ca (7.1.2-16)
CVE-2026-28689 (ImageMagick is free and open-source software used for editing and mani ...)
- TODO: check
+ - imagemagick <unfixed>
+ NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-493f-jh8w-qhx3
+ NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/3eb11260cfe84fddbdcb8d2ed47f92703d1b2987 (7.1.2-14)
+ NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/753ffb699934331b31028d4e271f2f6d6db85074 (7.1.2-16)
CVE-2026-28688 (ImageMagick is free and open-source software used for editing and mani ...)
- TODO: check
+ - imagemagick <unfixed>
+ NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xxw5-m53x-j38c
+ NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/40cfaa7b38729eb6a2808c9b94d6baa2fae6219b (7.1.2-14)
+ NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/e2d5b4ff0fb6abf2370af4b3dc483934b4dd63ff (7.1.2-14)
+ TODO: check if fixes in 7.1.2-14 are yet incomplte because claimed to be fixed in 7.1.2-16
CVE-2026-28687 (ImageMagick is free and open-source software used for editing and mani ...)
- TODO: check
+ - imagemagick <unfixed>
+ NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fpvf-frm6-625q
+ NOTE: Fixed by; https://github.com/ImageMagick/ImageMagick/commit/3392b4bba6ce076f4d88f5653a42d97b7e4f6970 (7.1.2-14)
+ NOTE: Fixed by; https://github.com/ImageMagick/ImageMagick6/commit/0e328007d2eeefb9ae24bc3f4442b1a2469d772e (6.9.13-39)
+ TODO: check, possibly missing followup, as claimed to be fixed in 7.1.2-16 and 6.9.13-41
CVE-2026-28686 (ImageMagick is free and open-source software used for editing and mani ...)
TODO: check
CVE-2026-28513 (Pocket ID is an OIDC provider that allows users to authenticate with t ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e14c981e414a45c33f438a76e4557a998277da8
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e14c981e414a45c33f438a76e4557a998277da8
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260310/984f2212/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list