Security fix for USN-7876-1 not backported to 24.04 LTS

Bug #2137579 reported by David Smith
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
imagemagick (Ubuntu)
New
Undecided
Unassigned

Bug Description

I have a number of Ubuntu servers (24.04.2 LTS, in AWS) with ImageMagick installed. They have the most recent version of ImageMagick and related packages installed, according to a grep of `apt list --installed`:

`imagemagick/noble,now 8:6.9.12.98+dfsg1-5.2build2 amd64 [installed]`

`apt update` followed by `apt list --upgradable` confirms that there are no newer versions available to me.

Assuming I'm reading the info in the "Code" tab of this site correctly, that version hasn't been updated in ~18 months. In the intervening period, a number of security issues have been reported that would seem to apply, including those in USN-7876-1 and USN-7756-1.

Ubuntu Pro includes backported fixes for these issues, and the USN pages for these issues direct me to download `8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm4` -- which isn't available to standard LTS users. Is there a plan/timeline for backporting the relevant security fixes to LTS?

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.