FFe: sync/merge imagemagick form unstable

Bug #1923350 reported by Matthias Klose
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
imagemagick (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

imagemagick is now in universe again, and wasn't merged / updated and only saw security updates since 2019. The package is mostly in sync with unstable, except for

    - SECURITY UPDATE: code execution vulnerabilities in ghostscript as
      invoked by imagemagick
      - debian/patches/200-disable-ghostscript-formats.patch: disable
        ghostscript handled types by default in policy.xml
      - debian/tests/rose-*: remove pdf tests.

I kept that patch, but it's one of this kind which breaks package builds, as seen at
Debian #986686.

Package builds, test builds available at
https://launchpad.net/~doko/+archive/ubuntu/toolchain/+sourcepub/12284194/+listing-archive-extra

Revision history for this message
Łukasz Zemczak (sil2100) wrote :

It's late, but I think it's not good for us to have outdated packages indeed. Especially popular packages, even in universe. Let's proceed, but please keep an eye out on it and make sure it's all good before Final Freeze.

Changed in imagemagick (Ubuntu):
status: New → Triaged
Revision history for this message
Launchpad Janitor (janitor) wrote :
Download full text (4.5 KiB)

This bug was fixed in the package imagemagick - 8:6.9.11.60+dfsg-1ubuntu1

---------------
imagemagick (8:6.9.11.60+dfsg-1ubuntu1) hirsute; urgency=medium

  * FFe: LP: #1923350.
  * Merge with Debian; remaining changes:
    - SECURITY UPDATE: code execution vulnerabilities in ghostscript as
      invoked by imagemagick
      - debian/patches/200-disable-ghostscript-formats.patch: disable
        ghostscript handled types by default in policy.xml
      - debian/tests/rose-*: remove pdf tests.
  * imagemagick is now in universe, so drop all the the patches removing
    build dependencies for main packages.

imagemagick (8:6.9.11.60+dfsg-1) unstable; urgency=high

  * New upstream version
    - Bug fix: "gscan2pdf tests fail", thanks to Sergio Durigan Junior
      (Closes: #980202).

imagemagick (8:6.9.11.58+dfsg-1) unstable; urgency=medium

  * New upstream version:
    - Fix error on i386 with php
  * Bug fix (workarround): "Many doubled www/www; broken links on
    index.html", thanks to 積丹尼 Dan Jacobson (Closes: #978138).

imagemagick (8:6.9.11.57+dfsg-1) unstable; urgency=medium

  * New upstream version:
    - Bug fix: "CVE-2020-29599", imagemagick mishandles the
      -authenticate option, which allows setting a password
      for password-protected PDF files. The user-controlled
      password was not properly escaped/sanitized and it
      was therefore possible to inject additional shell commands
      via coders/pdf.c. Thanks to Salvatore Bonaccorso
      (Closes: #977205).
    - Bug fix: "CVE-2020-27560: Division by Zero in function
      OptimizeLayerFrames", thanks to Salvatore Bonaccorso
      (Closes: #972797).
  * Fix dh_doxygen FTBFS (Closes: #971216)

imagemagick (8:6.9.11.24+dfsg-1) unstable; urgency=medium

  * Acknowledge NMU
  * New upstream version:
    - Fix CVE-2019-11470: Cineon image parsing DOS (Closes: #927830).
    - Fix CVE-2019-11472: XWD image parsing DOS (Closes: #927828).
    - Fix CVE-2020-13902: Heap based overflow in TIFF image decoding.
      (Closes: #928207).
    - Fix CVE-2019-11598: Heap-based buffer over-read in PNM image
      decoding (Closes: #928206).
    - Fix CVE-2019-12974: NULL pointer dereference in pango coder.
      (Closes: #931196).
    - Fix CVE-2019-12977: use of uninitialized value" vulnerability
      in the WriteJP2Image of jp2 coder (Closes: #931191).
    - Fix CVE-2019-12978: use of uninitialized value" vulnerability
      in the pango coder. (Closes: #931190).
    - Fix CVE-2019-12979: use of uninitialized value" vulnerability
      in MagickCore/image.c (Closes: #931189).
    - Fix CVE-2019-13135: use of uninitialized value" vulnerability
      in the cut coder (Closes: #932079).
    - Fix CVE-2019-13295: Heap-based buffer over-read in
      MagickCore/threshold.c (Closes: #931457).
    - Fix CVE-2019-13297: Heap-based buffer over-read in
      MagickCore/threshold.c (Closes: #931455).
    - Fix CVE-2019-13300: heap-based buffer overflow in
      MagickCore/statistic.c (Closes: #931454).
    - Fix CVE-2019-13304: stack-based buffer overflow for
      PNM image (Closes: #931453).
    - Fix CVE-2019-13305: stack-based buffer overflow for
      PNM image (Closes: #931452).
    - Fi...

Read more...

Changed in imagemagick (Ubuntu):
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.