CVE-2017-8350 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-8350): In ImageMagick 7.0.5-5, the ReadJNGImage function in png.c allows attackers to cause a denial of service (memory leak) via a crafted file.
Upstream patch: https://sourceforge.net/p/graphicsmagick/code/ci/639127f42a66eaf166f64d002e12bdbe4120acc0/ Do not cherry-pick! Fix consists of several parts.
x86 stable
amd64 stable
ia64 stable
ppc/ppc64 stable
hppa stable
sparc stable (thanks to Rolf Eike Beer)
Stable on alpha.
GLSA Vote: No @maintainers, please clean the vulnerable versions.
@maintainer(s), can 1.3.25 be cleaned?
Tree is clean: https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=fa5f4b10de851966308ec3a1dc04a725341af354