-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 21 Jul 2026 09:55:59 +0200 Source: imagemagick Binary: imagemagick-7-common imagemagick-7-doc libimage-magick-perl libmagick++-7-headers libmagick++-dev libmagickcore-7-headers libmagickcore-dev libmagickwand-7-headers libmagickwand-dev perlmagick Architecture: all Version: 8:7.1.1.43+dfsg1-1+deb13u12 Distribution: trixie Urgency: medium Maintainer: all Build Daemon (x86-grnet-02) Changed-By: Bastien Roucariès Description: imagemagick-7-common - image manipulation programs -- infrastructure imagemagick-7-doc - document files of ImageMagick libimage-magick-perl - Perl interface to the ImageMagick graphics routines libmagick++-7-headers - object-oriented C++ interface to ImageMagick - header files libmagick++-dev - object-oriented C++ interface to ImageMagick -- dummy package libmagickcore-7-headers - low-level image manipulation library - header files libmagickcore-dev - low-level image manipulation library -- dummy package libmagickwand-7-headers - image manipulation library - headers files libmagickwand-dev - image manipulation library -- dummy package perlmagick - Perl interface to ImageMagick -- dummy package Changes: imagemagick (8:7.1.1.43+dfsg1-1+deb13u12) trixie; urgency=medium . * Fix CVE-2026-56362: A heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow read affecting any writer calling GetPixelIndex. * Fix CVE-2026-56366: A memory leak vulnerability in the META reader when processing APP1JPEG input paths. * Fix CVE-2026-56372: A heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. * Fix CVE-2026-56373: A use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. * Fix CVE-2026-56374: A heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. * Fix CVE-2026-56375: A memory leak vulnerability in the ASHLAR coder when an action fails * Fix CVE-2026-61464: A heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title. * Fix CVE-2026-61465: A missing a check was found, for the allowed memory allocation limit in matrix-backed operations such as -canny. * Fix CVE-2026-61857: A heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. * Fix CVE-2026-61858: A policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. * Fix CVE-2026-61859: A policy bypass vulnerability in the -script operation due to missing security policy checks. * Fix CVE-2026-61860: a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to use memory that was already freed. * Fix CVE-2026-61861: A use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. * Fix CVE-2026-61862: When a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed. * Fix CVE-2026-61863: A memory leak in the TIFF encoder that occurs when a temporary file cannot be created, resulting in a small memory leak. * Fix CVE-2026-61864: A memory leak in color transformation to the log colorspace: when the operation fails, a small amount of memory is not released. * Fix CVE-2026-61865: A memory leak in the hough lines operation: when a specific operation fails, a small memory leak occurs. * Fix CVE-2026-61866: A memory leak vulnerability in the JNG encoder when a blob cannot be opened. * Fix CVE-2026-61867: A memory leak vulnerability in the TIFF encoder when memory allocation fails. * Fix CVE-2026-61868: a memory leak in the YUV decoder that occurs when opening of the blob fails. * Fix CVE-2026-61869: A memory leak in the MIFF encoder that occurs when a memory allocation fails during MIFF image processing. * Fix CVE-2026-61870: A memory leak vulnerability in the VIFF encoder when memory allocation fails. * Fix CVE-2026-61871: A memory leak in the ICON decoder that occurs when a memory allocation fails. * Fix CVE-2026-61872: a memory leak in the TIFF encoder when an invalid tiff:tile-geometry is specified. Checksums-Sha1: cd4f6e895292abd7f1a9033191a0384d2a31e388 77612 imagemagick-7-common_7.1.1.43+dfsg1-1+deb13u12_all.deb 424adfe5e33e93e24bd849691253b163db420099 9220636 imagemagick-7-doc_7.1.1.43+dfsg1-1+deb13u12_all.deb 128ec4ad93cd990a0ebecb09b21a092b092ca27f 19123 imagemagick_7.1.1.43+dfsg1-1+deb13u12_all-buildd.buildinfo e3df2273ee55d5e4d42badf235297b2a7b50df76 38920 libimage-magick-perl_7.1.1.43+dfsg1-1+deb13u12_all.deb 0fb51399b6f796a0cb959a6b7777ebd21dd7a0a0 47652 libmagick++-7-headers_7.1.1.43+dfsg1-1+deb13u12_all.deb 6082539434408f57f40efc928e0f4d066a56ca35 1188 libmagick++-dev_7.1.1.43+dfsg1-1+deb13u12_all.deb b2f58b7f1d68642301807b8bd8271f0e3b549590 50440 libmagickcore-7-headers_7.1.1.43+dfsg1-1+deb13u12_all.deb 2165249b3e8f9c88b0fef209f439a8437c586902 1164 libmagickcore-dev_7.1.1.43+dfsg1-1+deb13u12_all.deb bef92023afb9a9b33beb9cf260d93e8409df3323 9864 libmagickwand-7-headers_7.1.1.43+dfsg1-1+deb13u12_all.deb 2618bd5676c55df7e7da696be4d7dc344383b6c4 1148 libmagickwand-dev_7.1.1.43+dfsg1-1+deb13u12_all.deb b693e9dfb872cf0cb2670fee6670e82081d360b4 1192 perlmagick_7.1.1.43+dfsg1-1+deb13u12_all.deb Checksums-Sha256: f3f040a8186c123690df07c7b3d3e08c7c2741a2c76c7496f27745b63f9ec192 77612 imagemagick-7-common_7.1.1.43+dfsg1-1+deb13u12_all.deb 2f3d441add9aa70faf667e3fd0aa7f09b90c1a783ab73fdf24dfb35a6032a590 9220636 imagemagick-7-doc_7.1.1.43+dfsg1-1+deb13u12_all.deb 2f18161e8ffdeff3d8a8aaead88c632384f9507f4c7f9be1f35fb48ba35f30e8 19123 imagemagick_7.1.1.43+dfsg1-1+deb13u12_all-buildd.buildinfo 6b09088cf70d7c25c344cba8d24758543503cc000f91bafc7abf0724dc28471d 38920 libimage-magick-perl_7.1.1.43+dfsg1-1+deb13u12_all.deb 90ff04be40a7b7505ee7d29600fb4ab0c06287fb07a3860433f44576a2004d93 47652 libmagick++-7-headers_7.1.1.43+dfsg1-1+deb13u12_all.deb 4c6aa27c10516c52a80d180f864bee250d5e81c8615a98491a9696c8ef08059b 1188 libmagick++-dev_7.1.1.43+dfsg1-1+deb13u12_all.deb 846f5155d9805d0af255cdd67d08723c1de80df65615aba9f107ffe6176981e4 50440 libmagickcore-7-headers_7.1.1.43+dfsg1-1+deb13u12_all.deb 38fa640179f964af849e6a616ecbef896d45c2805b6d6c8cc9c61cfe1e46ea00 1164 libmagickcore-dev_7.1.1.43+dfsg1-1+deb13u12_all.deb e012fa3aeeee4b4c0dbc73bea2c1f7b43e38003433dd2fbea8808976be6d8528 9864 libmagickwand-7-headers_7.1.1.43+dfsg1-1+deb13u12_all.deb 4b2c3e59be3dc79dfad9d2d5e15b20655b59aa7918680107ba43d8111fae5af0 1148 libmagickwand-dev_7.1.1.43+dfsg1-1+deb13u12_all.deb 9be3a80bd6f46e56377d240dfdf4e096a9a8867bd8472ca4b89dde72682b7627 1192 perlmagick_7.1.1.43+dfsg1-1+deb13u12_all.deb Files: 872c88d53f5ada1b9264ab5af82adb29 77612 graphics optional imagemagick-7-common_7.1.1.43+dfsg1-1+deb13u12_all.deb 543287a1623fb69b092269df87e74368 9220636 doc optional imagemagick-7-doc_7.1.1.43+dfsg1-1+deb13u12_all.deb f6c9a299a0066acd21830226ce6e62c7 19123 graphics optional imagemagick_7.1.1.43+dfsg1-1+deb13u12_all-buildd.buildinfo 07e160f2990f8d0ef8b8652ad5eb4ba2 38920 perl optional libimage-magick-perl_7.1.1.43+dfsg1-1+deb13u12_all.deb cf8d8e8fde7c21f83e1a1578708b435c 47652 libdevel optional libmagick++-7-headers_7.1.1.43+dfsg1-1+deb13u12_all.deb 15405de0a01fb4a756d330b4586c56c4 1188 oldlibs optional libmagick++-dev_7.1.1.43+dfsg1-1+deb13u12_all.deb 3629af972e0f3172c25a54a8397197ab 50440 libdevel optional libmagickcore-7-headers_7.1.1.43+dfsg1-1+deb13u12_all.deb 2c24657c0d025d80dcfd09b2775453e4 1164 oldlibs optional libmagickcore-dev_7.1.1.43+dfsg1-1+deb13u12_all.deb 7701b38691fee5cc3e050efd082aaa17 9864 libdevel optional libmagickwand-7-headers_7.1.1.43+dfsg1-1+deb13u12_all.deb 18f3723058c26bf6d2b63e5bdb1a76b0 1148 oldlibs optional libmagickwand-dev_7.1.1.43+dfsg1-1+deb13u12_all.deb d65da456a1f9319b9525a5afe261982e 1192 oldlibs optional perlmagick_7.1.1.43+dfsg1-1+deb13u12_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE81O8NL+3kjBAqEvLmgPNRvTf/zcFAmqataUACgkQmgPNRvTf /zeXOg/+LKpuHrLAHDobbEgrrGeggVI5c4Lf+CTEB9n+gIgH7j8d06b5bwDSR3mz 2PAkHw4xl/KgUHBTjZDkl+mwqgg+7gQR5rSRNOfKfkvNxgPlUN0PH4K3jIJbjOQL xfOy+nRtwtXDweZO7D4EoriiGFnmbKib2kUz6/CnuUFixuEzdJovgdrzwk/vClUc nrrOCUb3l0EJAiIi5IpjmZVB1rPtrwp/4CHHdO9O0RbwB7A8HZIb5PpfcerwPJRd x9CMeTeePVhoMZNpn75Wc9v4uGrZgRJusRxESZkCqp3NjEBANN9eAlp1iU6jsx5N TYYrSnThruOr0QV9HYYD6ZXY2xvY3oR4t9afIlvBdHw4BJVbKdHJyt/C2lXvFvqD h2uAKgpx24BsjWNLgG4NMfo0JLT45VIgb/CVlyoeZNMIIX8KTmwELvF68fhzaXv+ LQxgJ2HzSCSyuFC5LMvFJpwmZLlSGA4/rp/jzHuYQxvHgqtqsQ+agAHZFvnUMIDm QKClSnm5fDyRae71nLpjPJv02OLuUI48VDhIf7nVjyFlBkGUIxJ3vG6rCxCtrsWm C/Mjwb8zYePIxnym0n4r3ClDzSRuwLwRLRKM73h4Z8cA4+5d688kria5EbnSxXXJ uH5WRW3S2xCn1qSQZCa+Kh8C1xJRB78k38+dt4m00moo1JpLQUI= =3hml -----END PGP SIGNATURE-----