Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.1.2.2023.3429
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DLA-3429-1)
Summary:The remote host is missing an update for the Debian 'imagemagick' package(s) announced via the DLA-3429-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'imagemagick' package(s) announced via the DLA-3429-1 advisory.

Vulnerability Insight:
Multiple vulnerabilities were fixed in imagemagick, a software suite, used for editing and manipulating digital images.

CVE-2021-20176

A divide by zero was found in gem.c file.

CVE-2021-20241

A divide by zero was found in jp2 coder.

CVE-2021-20243

A divide by zero was found in dcm coder.

CVE-2021-20244

A divide by zero was found in fx.c.

CVE-2021-20245

A divide by zero was found in webp coder.

CVE-2021-20246

A divide by zero was found in resample.c.

CVE-2021-20309

A divide by zero was found in WaveImage.c

CVE-2021-20312

An integer overflow was found in WriteTHUMBNAILImage() of coders/thumbnail.c

CVE-2021-20313

A potential cipher leak was found when the calculate signatures in TransformSignature().

CVE-2021-39212

A policy bypass was found for postscript files.

CVE-2022-28463

A bufer overflow was found in buffer overflow in cin coder.

CVE-2022-32545

A undefined behavior (conversion outside the range of representable values of type unsigned char) was found in psd file handling.

CVE-2022-32546

A undefined behavior (conversion outside the range of representable values of type long) was found in pcl file handling.

CVE-2022-32547

An unaligned access was found in property.c

For Debian 10 buster, these problems have been fixed in version 8:6.9.10.23+dfsg-2.1+deb10u5.

We recommend that you upgrade your imagemagick packages.

For the detailed security status of imagemagick please refer to its security tracker page at: [link moved to references]

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: [link moved to references]

Affected Software/OS:
'imagemagick' package(s) on Debian 10.

Solution:
Please install the updated package(s).

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2021-20176
https://bugzilla.redhat.com/show_bug.cgi?id=1916610
https://lists.debian.org/debian-lts-announce/2021/03/msg00030.html
https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html
Common Vulnerability Exposure (CVE) ID: CVE-2021-20241
https://bugzilla.redhat.com/show_bug.cgi?id=1928952
https://github.com/ImageMagick/ImageMagick/pull/3177
Common Vulnerability Exposure (CVE) ID: CVE-2021-20243
https://bugzilla.redhat.com/show_bug.cgi?id=1928958
https://github.com/ImageMagick/ImageMagick/pull/3193
https://lists.debian.org/debian-lts-announce/2021/06/msg00000.html
Common Vulnerability Exposure (CVE) ID: CVE-2021-20244
https://bugzilla.redhat.com/show_bug.cgi?id=1928959
https://github.com/ImageMagick/ImageMagick/pull/3194
Common Vulnerability Exposure (CVE) ID: CVE-2021-20245
https://bugzilla.redhat.com/show_bug.cgi?id=1928943
https://github.com/ImageMagick/ImageMagick/issues/3176
Common Vulnerability Exposure (CVE) ID: CVE-2021-20246
https://bugzilla.redhat.com/show_bug.cgi?id=1928941
Common Vulnerability Exposure (CVE) ID: CVE-2021-20309
https://bugzilla.redhat.com/show_bug.cgi?id=1946722
Common Vulnerability Exposure (CVE) ID: CVE-2021-20312
https://bugzilla.redhat.com/show_bug.cgi?id=1946742
Common Vulnerability Exposure (CVE) ID: CVE-2021-20313
https://bugzilla.redhat.com/show_bug.cgi?id=1947019
Common Vulnerability Exposure (CVE) ID: CVE-2021-39212
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qvhr-jj4p-j2qr
https://github.com/ImageMagick/ImageMagick/commit/01faddbe2711a4156180c4a92837e2f23683cc68
https://github.com/ImageMagick/ImageMagick/commit/35893e7cad78ce461fcaffa56076c11700ba5e4e
Common Vulnerability Exposure (CVE) ID: CVE-2022-28463
https://github.com/ImageMagick/ImageMagick/commit/ca3654ebf7a439dc736f56f083c9aa98e4464b7f
https://github.com/ImageMagick/ImageMagick/issues/4988
https://github.com/ImageMagick/ImageMagick6/commit/e6ea5876e0228165ee3abc6e959aa174cee06680
https://lists.debian.org/debian-lts-announce/2022/05/msg00018.html
Common Vulnerability Exposure (CVE) ID: CVE-2022-32545
https://bugzilla.redhat.com/show_bug.cgi?id=2091811
https://github.com/ImageMagick/ImageMagick/commit/9c9a84cec4ab28ee0b57c2b9266d6fbe68183512
https://github.com/ImageMagick/ImageMagick6/commit/450949ed017f009b399c937cf362f0058eacc5fa
Common Vulnerability Exposure (CVE) ID: CVE-2022-32546
https://bugzilla.redhat.com/show_bug.cgi?id=2091812
https://github.com/ImageMagick/ImageMagick/commit/f221ea0fa3171f0f4fdf74ac9d81b203b9534c23
https://github.com/ImageMagick/ImageMagick6/commit/29c8abce0da56b536542f76a9ddfebdaab5b2943
Common Vulnerability Exposure (CVE) ID: CVE-2022-32547
https://bugzilla.redhat.com/show_bug.cgi?id=2091813
https://github.com/ImageMagick/ImageMagick/commit/eac8ce4d873f28bb6a46aa3a662fb196b49b95d0
https://github.com/ImageMagick/ImageMagick6/commit/dc070da861a015d3c97488fdcca6063b44d47a7b
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.