Summary: | <media-gfx/imagemagick-{6.9.12.88,7.1.1.11}: multiple vulnerabilities | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | ||
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B1 [glsa+] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 907992, 907993 | ||
Bug Blocks: |
Description
John Helmert III
![]() ![]() ![]() ![]() Are there fixes for CVE-2023-2157 and CVE-2023-34153 in 6.x? (In reply to John Helmert III from comment #1) > Are there fixes for CVE-2023-2157 and CVE-2023-34153 in 6.x? CVE-2023-2157: - https://github.com/ImageMagick/ImageMagick6/commit/7e4c992f148afc5b28111e540921d5b6e4e38673 (note that jxc isn't supported in IM6) CVE-2023-34153: not sure, need to inspect the IM7 changes (https://github.com/ImageMagick/ImageMagick/commit/d31c80d15a2c82fc1dd8e889e0f97b0219079a57) and compare the relevant files Thanks! commit 2093f1a80afe379b2f1e5eeee9c125dc26a21b59 Author: Sam James <sam@gentoo.org> Date: Thu Dec 28 04:34:07 2023 +0000 media-gfx/imagemagick: drop versions Signed-off-by: Sam James <sam@gentoo.org> Cleanup done The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=4a7120d937eaaec2a14046c3d00320bd902c32bf commit 4a7120d937eaaec2a14046c3d00320bd902c32bf Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2024-05-04 06:13:29 +0000 Commit: Hans de Graaff <graaff@gentoo.org> CommitDate: 2024-05-04 06:14:05 +0000 [ GLSA 202405-02 ] ImageMagick: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/835931 Bug: https://bugs.gentoo.org/843833 Bug: https://bugs.gentoo.org/852947 Bug: https://bugs.gentoo.org/871954 Bug: https://bugs.gentoo.org/893526 Bug: https://bugs.gentoo.org/904357 Bug: https://bugs.gentoo.org/908082 Bug: https://bugs.gentoo.org/917594 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: Hans de Graaff <graaff@gentoo.org> glsa-202405-02.xml | 74 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 74 insertions(+) |