[Pkg-gmagick-im-team] imagemagick_7.1.1.43+dfsg1-1+deb13u12_source.changes ACCEPTED into proposed-updates->stable-new

Debian FTP Masters ftpmaster at ftp-master.debian.org
Wed Aug 5 09:17:59 BST 2026


Thank you for your contribution to Debian.

Mapping trixie to stable.
Mapping stable to proposed-updates.

Accepted:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 21 Jul 2026 09:55:59 +0200
Source: imagemagick
Architecture: source
Version: 8:7.1.1.43+dfsg1-1+deb13u12
Distribution: trixie
Urgency: medium
Maintainer: ImageMagick Packaging Team <pkg-gmagick-im-team at lists.alioth.debian.org>
Changed-By: Bastien Roucariès <rouca at debian.org>
Changes:
 imagemagick (8:7.1.1.43+dfsg1-1+deb13u12) trixie; urgency=medium
 .
   * Fix CVE-2026-56362:
     A heap-buffer-overflow read vulnerability in GetPixelIndex caused
     by OpenPixelCache updating image channel metadata before pixel
     cache memory allocation. Attackers can trigger memory and
     disk allocation failures to cause a heap-buffer-overflow
     read affecting any writer calling GetPixelIndex.
   * Fix CVE-2026-56366:
     A memory leak vulnerability in the META reader
     when processing APP1JPEG input paths.
   * Fix CVE-2026-56372:
     A heap buffer overflow vulnerability in the magnify operation
     that allows attackers to read out of bounds memory.
   * Fix CVE-2026-56373:
     A use-after-free vulnerability in the PDB decoder that
     uses a stale pointer when memory allocation fails.
   * Fix CVE-2026-56374:
     A heap buffer overflow vulnerability in the FTXT encoder
     due to missing boundary checks when parsing ftxt:format.
   * Fix CVE-2026-56375:
     A memory leak vulnerability in the ASHLAR coder when
     an action fails
   * Fix CVE-2026-61464:
     A heap-based buffer over-write vulnerability that occurs
     when running an X11 import with a crafted window title.
   * Fix CVE-2026-61465:
     A missing a check was found, for the allowed memory allocation
     limit in matrix-backed operations such as -canny.
   * Fix CVE-2026-61857:
     A heap use-after-free vulnerability caused by missing null
     check when parsing XMP profiles.
   * Fix CVE-2026-61858:
     A policy bypass vulnerability in the APNG encoder and
     external delegates due to missing validation checks.
   * Fix CVE-2026-61859:
     A policy bypass vulnerability in the -script operation due
     to missing security policy checks.
   * Fix CVE-2026-61860:
     a use-after-free vulnerability that occurs when freetype
     initialization fails: the method does not exit and
     continues to use memory that was already freed.
   * Fix CVE-2026-61861:
     A use-after-free vulnerability in the FormatMagickCaption method
     when memory allocation fails.
   * Fix CVE-2026-61862:
     When a profile is displayed with the identify command and the
     profile value is not printable, a single byte at the end of the
     profile can be printed.
   * Fix CVE-2026-61863:
     A memory leak in the TIFF encoder that occurs when a temporary
     file cannot be created, resulting in a small memory leak.
   * Fix CVE-2026-61864:
     A memory leak in color transformation to the log colorspace:
     when the operation fails, a small amount of memory is not released.
   * Fix CVE-2026-61865:
     A memory leak in the hough lines operation: when a specific operation fails,
     a small memory leak occurs.
   * Fix CVE-2026-61866:
     A memory leak vulnerability in the JNG encoder when a blob cannot be opened.
   * Fix CVE-2026-61867:
     A memory leak vulnerability in the TIFF encoder when memory allocation fails.
   * Fix CVE-2026-61868:
     a memory leak in the YUV decoder that occurs when opening of the blob fails.
   * Fix CVE-2026-61869:
     A memory leak in the MIFF encoder that occurs when a memory allocation
     fails during MIFF image processing.
   * Fix CVE-2026-61870:
     A memory leak vulnerability in the VIFF encoder when memory allocation fails.
   * Fix CVE-2026-61871:
     A memory leak in the ICON decoder that occurs when a memory allocation fails.
   * Fix CVE-2026-61872:
     a memory leak in the TIFF encoder when an invalid tiff:tile-geometry
     is specified.
Checksums-Sha1:
 5b646841a7a4f3ec8617e000913203f9c26b6977 5263 imagemagick_7.1.1.43+dfsg1-1+deb13u12.dsc
 103af0af388a733c043845b228cf3031c16d859b 10501740 imagemagick_7.1.1.43+dfsg1.orig.tar.xz
 f113f2657e3f88fcea4c22927316053cf595fd60 366728 imagemagick_7.1.1.43+dfsg1-1+deb13u12.debian.tar.xz
 3f0b7d64c26d9044c613beb93523e2bd5f8e35e7 8935 imagemagick_7.1.1.43+dfsg1-1+deb13u12_source.buildinfo
Checksums-Sha256:
 d82041b1f5888ca181eeb4316981c31ae9d9c54060f1f4ec10a2d23dd80c8aeb 5263 imagemagick_7.1.1.43+dfsg1-1+deb13u12.dsc
 bcb4f3c78a930a608fa4889f889edbcb384974246ad9407fce1858f2c0607bfe 10501740 imagemagick_7.1.1.43+dfsg1.orig.tar.xz
 4ab5e32a172da4a244afa140570d1c48fd48d5c7a64dfce6704917f30081c9f3 366728 imagemagick_7.1.1.43+dfsg1-1+deb13u12.debian.tar.xz
 d96f4c803f8caa151ba791817d9f1a3cc551aa3aad4c5e606d2fc70c63a8ce0b 8935 imagemagick_7.1.1.43+dfsg1-1+deb13u12_source.buildinfo
Files:
 dd2d3dcebca275f2cc20be646e49953d 5263 graphics optional imagemagick_7.1.1.43+dfsg1-1+deb13u12.dsc
 01cfb13a7c1813afb50790e431358c6c 10501740 graphics optional imagemagick_7.1.1.43+dfsg1.orig.tar.xz
 83899433bcf397389cbd017d3517492b 366728 graphics optional imagemagick_7.1.1.43+dfsg1-1+deb13u12.debian.tar.xz
 7b3b28f766199c8a7dff292caf2e6616 8935 graphics optional imagemagick_7.1.1.43+dfsg1-1+deb13u12_source.buildinfo

-----BEGIN PGP SIGNATURE-----

wsG7BAEBCgBvBYJqcu8ACRAAOhotqkEIX0cUAAAAAAAeACBzYWx0QG5vdGF0aW9u
cy5zZXF1b2lhLXBncC5vcmc0rkoyWYM3Th4M/pe94DJUFQ5DCyAlqavU1xS89sMW
ZRYhBF0Bh7lAokW617D1agA6Gi2qQQhfAAA3sA//V5ydzV6r4T+k8V7FMMJ9CFCA
WG9T7t0vhtCWNfNRy2Vbqs/yJmcsdPfTipV81+6gEBW63Pyco1kRNf6GNnE90X7k
hS1cmWzxJtbmHrR3DR6pHOrZj1BYS7Ow/3jKzStqnHWHkj4xy+BFMaWnBDaA8s/U
qwC86Ve7fUR8YeZLRYH74L1E1pXoM/5awFsIWxCpqnbU/yTkgaScg8nYZ7e4qPP4
4UFHYGITpgaLwhTwLJwn/BmGqP/zFo7HDMr1CJMRx6EmNzjlOo5WwFPRMeUme2+B
769JsOxjtmPqxTED2o0huLzlTJCE+tlSbuD5FLz4WpICb/VLgCSSU8eWApEtIUkE
9QabH9Hz6G99jEz1qmroPLF2wsRpWbJYg7HryqJlzasgn2v9NX5imVIgOblBgKzQ
WYjJTk1iZzPqG1mPXvD7vBfqhZSlpixepVDx7MEakcIsx47xdPEBbNp2Kl1DxMhg
b7jMyZ0RmAab/i07M/8oec4A/heZYMvFHMsjzEYRr2QoU6WAPMBdUSZXMp7nyeJw
QFNQAOQBLQzxzoFCikU/7e5Ha/JeBdU4vPTGgc0rVFWWFNj07ehxNBCE//YunIfe
h4VxaNP36rmiJwGTxCyWHhQzlY1Rl7aZaX8KcuGEAP9mUck9Ke51MtfgthOV5Z76
KmZ57dWz+Usf9wNfUC0=
=MKhs
-----END PGP SIGNATURE-----

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-gmagick-im-team/attachments/20260805/36daf0fb/attachment.sig>


More information about the Pkg-gmagick-im-team mailing list