[Git][security-tracker-team/security-tracker][master] CVE-2026-28688/imagemagick6

Bastien Roucariès (@rouca) rouca at debian.org
Tue Mar 17 14:51:50 GMT 2026



Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a44f6a37 by Bastien Roucariès at 2026-03-17T15:51:22+01:00
CVE-2026-28688/imagemagick6

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3340,7 +3340,8 @@ CVE-2026-28688 (ImageMagick is free and open-source software used for editing an
 	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xxw5-m53x-j38c
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/40cfaa7b38729eb6a2808c9b94d6baa2fae6219b (7.1.2-14)
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/e2d5b4ff0fb6abf2370af4b3dc483934b4dd63ff (7.1.2-14)
-	TODO: check if fixes in 7.1.2-14 are yet incomplte because claimed to be fixed in 7.1.2-16
+	TODO: For imagemagick6 by fix inside jumbo patch for CVE-2026-28686, first patch was incomplete
+	TODO: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/6a602fb36f181a0089848344a3b0d79fc6155a2b (6.9.13-41)
 CVE-2026-28687 (ImageMagick is free and open-source software used for editing and mani ...)
 	- imagemagick 8:7.1.2.16+dfsg1-1
 	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fpvf-frm6-625q



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a44f6a373a8a824b7f52045b12c1b9b112233ace

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a44f6a373a8a824b7f52045b12c1b9b112233ace
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260317/fd84e8ce/attachment.htm>


More information about the debian-security-tracker-commits mailing list