Description: | Summary: The remote host is missing an update for the Debian 'imagemagick' package(s) announced via the DLA-3429-1 advisory.
Vulnerability Insight: Multiple vulnerabilities were fixed in imagemagick, a software suite, used for editing and manipulating digital images.
CVE-2021-20176
A divide by zero was found in gem.c file.
CVE-2021-20241
A divide by zero was found in jp2 coder.
CVE-2021-20243
A divide by zero was found in dcm coder.
CVE-2021-20244
A divide by zero was found in fx.c.
CVE-2021-20245
A divide by zero was found in webp coder.
CVE-2021-20246
A divide by zero was found in resample.c.
CVE-2021-20309
A divide by zero was found in WaveImage.c
CVE-2021-20312
An integer overflow was found in WriteTHUMBNAILImage() of coders/thumbnail.c
CVE-2021-20313
A potential cipher leak was found when the calculate signatures in TransformSignature().
CVE-2021-39212
A policy bypass was found for postscript files.
CVE-2022-28463
A bufer overflow was found in buffer overflow in cin coder.
CVE-2022-32545
A undefined behavior (conversion outside the range of representable values of type unsigned char) was found in psd file handling.
CVE-2022-32546
A undefined behavior (conversion outside the range of representable values of type long) was found in pcl file handling.
CVE-2022-32547
An unaligned access was found in property.c
For Debian 10 buster, these problems have been fixed in version 8:6.9.10.23+dfsg-2.1+deb10u5.
We recommend that you upgrade your imagemagick packages.
For the detailed security status of imagemagick please refer to its security tracker page at: [link moved to references]
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: [link moved to references]
Affected Software/OS: 'imagemagick' package(s) on Debian 10.
Solution: Please install the updated package(s).
CVSS Score: 7.8
CVSS Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C
|