[Pkg-gmagick-im-team] imagemagick_7.1.1.43+dfsg1-1+deb13u12_source.changes ACCEPTED into proposed-updates->stable-new
Debian FTP Masters
ftpmaster at ftp-master.debian.org
Wed Aug 5 09:17:59 BST 2026
Thank you for your contribution to Debian.
Mapping trixie to stable.
Mapping stable to proposed-updates.
Accepted:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 21 Jul 2026 09:55:59 +0200
Source: imagemagick
Architecture: source
Version: 8:7.1.1.43+dfsg1-1+deb13u12
Distribution: trixie
Urgency: medium
Maintainer: ImageMagick Packaging Team <pkg-gmagick-im-team at lists.alioth.debian.org>
Changed-By: Bastien Roucariès <rouca at debian.org>
Changes:
imagemagick (8:7.1.1.43+dfsg1-1+deb13u12) trixie; urgency=medium
.
* Fix CVE-2026-56362:
A heap-buffer-overflow read vulnerability in GetPixelIndex caused
by OpenPixelCache updating image channel metadata before pixel
cache memory allocation. Attackers can trigger memory and
disk allocation failures to cause a heap-buffer-overflow
read affecting any writer calling GetPixelIndex.
* Fix CVE-2026-56366:
A memory leak vulnerability in the META reader
when processing APP1JPEG input paths.
* Fix CVE-2026-56372:
A heap buffer overflow vulnerability in the magnify operation
that allows attackers to read out of bounds memory.
* Fix CVE-2026-56373:
A use-after-free vulnerability in the PDB decoder that
uses a stale pointer when memory allocation fails.
* Fix CVE-2026-56374:
A heap buffer overflow vulnerability in the FTXT encoder
due to missing boundary checks when parsing ftxt:format.
* Fix CVE-2026-56375:
A memory leak vulnerability in the ASHLAR coder when
an action fails
* Fix CVE-2026-61464:
A heap-based buffer over-write vulnerability that occurs
when running an X11 import with a crafted window title.
* Fix CVE-2026-61465:
A missing a check was found, for the allowed memory allocation
limit in matrix-backed operations such as -canny.
* Fix CVE-2026-61857:
A heap use-after-free vulnerability caused by missing null
check when parsing XMP profiles.
* Fix CVE-2026-61858:
A policy bypass vulnerability in the APNG encoder and
external delegates due to missing validation checks.
* Fix CVE-2026-61859:
A policy bypass vulnerability in the -script operation due
to missing security policy checks.
* Fix CVE-2026-61860:
a use-after-free vulnerability that occurs when freetype
initialization fails: the method does not exit and
continues to use memory that was already freed.
* Fix CVE-2026-61861:
A use-after-free vulnerability in the FormatMagickCaption method
when memory allocation fails.
* Fix CVE-2026-61862:
When a profile is displayed with the identify command and the
profile value is not printable, a single byte at the end of the
profile can be printed.
* Fix CVE-2026-61863:
A memory leak in the TIFF encoder that occurs when a temporary
file cannot be created, resulting in a small memory leak.
* Fix CVE-2026-61864:
A memory leak in color transformation to the log colorspace:
when the operation fails, a small amount of memory is not released.
* Fix CVE-2026-61865:
A memory leak in the hough lines operation: when a specific operation fails,
a small memory leak occurs.
* Fix CVE-2026-61866:
A memory leak vulnerability in the JNG encoder when a blob cannot be opened.
* Fix CVE-2026-61867:
A memory leak vulnerability in the TIFF encoder when memory allocation fails.
* Fix CVE-2026-61868:
a memory leak in the YUV decoder that occurs when opening of the blob fails.
* Fix CVE-2026-61869:
A memory leak in the MIFF encoder that occurs when a memory allocation
fails during MIFF image processing.
* Fix CVE-2026-61870:
A memory leak vulnerability in the VIFF encoder when memory allocation fails.
* Fix CVE-2026-61871:
A memory leak in the ICON decoder that occurs when a memory allocation fails.
* Fix CVE-2026-61872:
a memory leak in the TIFF encoder when an invalid tiff:tile-geometry
is specified.
Checksums-Sha1:
5b646841a7a4f3ec8617e000913203f9c26b6977 5263 imagemagick_7.1.1.43+dfsg1-1+deb13u12.dsc
103af0af388a733c043845b228cf3031c16d859b 10501740 imagemagick_7.1.1.43+dfsg1.orig.tar.xz
f113f2657e3f88fcea4c22927316053cf595fd60 366728 imagemagick_7.1.1.43+dfsg1-1+deb13u12.debian.tar.xz
3f0b7d64c26d9044c613beb93523e2bd5f8e35e7 8935 imagemagick_7.1.1.43+dfsg1-1+deb13u12_source.buildinfo
Checksums-Sha256:
d82041b1f5888ca181eeb4316981c31ae9d9c54060f1f4ec10a2d23dd80c8aeb 5263 imagemagick_7.1.1.43+dfsg1-1+deb13u12.dsc
bcb4f3c78a930a608fa4889f889edbcb384974246ad9407fce1858f2c0607bfe 10501740 imagemagick_7.1.1.43+dfsg1.orig.tar.xz
4ab5e32a172da4a244afa140570d1c48fd48d5c7a64dfce6704917f30081c9f3 366728 imagemagick_7.1.1.43+dfsg1-1+deb13u12.debian.tar.xz
d96f4c803f8caa151ba791817d9f1a3cc551aa3aad4c5e606d2fc70c63a8ce0b 8935 imagemagick_7.1.1.43+dfsg1-1+deb13u12_source.buildinfo
Files:
dd2d3dcebca275f2cc20be646e49953d 5263 graphics optional imagemagick_7.1.1.43+dfsg1-1+deb13u12.dsc
01cfb13a7c1813afb50790e431358c6c 10501740 graphics optional imagemagick_7.1.1.43+dfsg1.orig.tar.xz
83899433bcf397389cbd017d3517492b 366728 graphics optional imagemagick_7.1.1.43+dfsg1-1+deb13u12.debian.tar.xz
7b3b28f766199c8a7dff292caf2e6616 8935 graphics optional imagemagick_7.1.1.43+dfsg1-1+deb13u12_source.buildinfo
-----BEGIN PGP SIGNATURE-----
wsG7BAEBCgBvBYJqcu8ACRAAOhotqkEIX0cUAAAAAAAeACBzYWx0QG5vdGF0aW9u
cy5zZXF1b2lhLXBncC5vcmc0rkoyWYM3Th4M/pe94DJUFQ5DCyAlqavU1xS89sMW
ZRYhBF0Bh7lAokW617D1agA6Gi2qQQhfAAA3sA//V5ydzV6r4T+k8V7FMMJ9CFCA
WG9T7t0vhtCWNfNRy2Vbqs/yJmcsdPfTipV81+6gEBW63Pyco1kRNf6GNnE90X7k
hS1cmWzxJtbmHrR3DR6pHOrZj1BYS7Ow/3jKzStqnHWHkj4xy+BFMaWnBDaA8s/U
qwC86Ve7fUR8YeZLRYH74L1E1pXoM/5awFsIWxCpqnbU/yTkgaScg8nYZ7e4qPP4
4UFHYGITpgaLwhTwLJwn/BmGqP/zFo7HDMr1CJMRx6EmNzjlOo5WwFPRMeUme2+B
769JsOxjtmPqxTED2o0huLzlTJCE+tlSbuD5FLz4WpICb/VLgCSSU8eWApEtIUkE
9QabH9Hz6G99jEz1qmroPLF2wsRpWbJYg7HryqJlzasgn2v9NX5imVIgOblBgKzQ
WYjJTk1iZzPqG1mPXvD7vBfqhZSlpixepVDx7MEakcIsx47xdPEBbNp2Kl1DxMhg
b7jMyZ0RmAab/i07M/8oec4A/heZYMvFHMsjzEYRr2QoU6WAPMBdUSZXMp7nyeJw
QFNQAOQBLQzxzoFCikU/7e5Ha/JeBdU4vPTGgc0rVFWWFNj07ehxNBCE//YunIfe
h4VxaNP36rmiJwGTxCyWHhQzlY1Rl7aZaX8KcuGEAP9mUck9Ke51MtfgthOV5Z76
KmZ57dWz+Usf9wNfUC0=
=MKhs
-----END PGP SIGNATURE-----
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-gmagick-im-team/attachments/20260805/36daf0fb/attachment.sig>
More information about the Pkg-gmagick-im-team
mailing list