Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 562892 - <media-gfx/imagemagick-6.8.9: multiple vulnerabilities
Summary: <media-gfx/imagemagick-6.8.9: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B2 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2015-10-12 07:57 UTC by Agostino Sarubbo
Modified: 2016-06-26 13:54 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2015-10-12 07:57:31 UTC
From ${URL} :

Moshe Kaplan has reported three flaws in ImageMagick to the Ubuntu
bugtracker and ImageMagick upstream.

https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1459747
Reportedly fixed with:
https://github.com/ImageMagick/ImageMagick/commit/0f6fc2d5bf8f500820c3dbcf0d23ee14f2d9f734

https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1490362
Reportedly fixed with:
https://github.com/ImageMagick/ImageMagick/commit/4f68e9661518463fca523c9726bb5d940a2aa6d8

https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1448803
Fix unknown.

The bugs include stacktraces and reproducer inputs.



@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2016-03-14 10:17:09 UTC
(In reply to Agostino Sarubbo from comment #0)
> From ${URL} :
> 
> Moshe Kaplan has reported three flaws in ImageMagick to the Ubuntu
> bugtracker and ImageMagick upstream.
> 
> https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1459747
> Reportedly fixed with:
> https://github.com/ImageMagick/ImageMagick/commit/
> 0f6fc2d5bf8f500820c3dbcf0d23ee14f2d9f734
> 
> https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1490362
> Reportedly fixed with:
> https://github.com/ImageMagick/ImageMagick/commit/
> 4f68e9661518463fca523c9726bb5d940a2aa6d8
> 
> https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1448803
> Fix unknown.
> 
> The bugs include stacktraces and reproducer inputs.
> 
> 
> 
> @maintainer(s): after the bump, in case we need to stabilize the package,
> please let us know if it is ready for the stabilization or not.

Following those links shows that the bug was fixed in imagemagick 6.8.9.  6.9.0.3 is in Portage already stable.

Added to existing GLSA
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2016-06-26 13:54:32 UTC
This issue was resolved and addressed in
 GLSA 201606-14 at https://security.gentoo.org/glsa/201606-14
by GLSA coordinator Aaron Bauman (b-man).