-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2020.3057
                        imagemagick security update
                             8 September 2020

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           imagemagick
Publisher:         Debian
Operating System:  Debian GNU/Linux 9
Impact/Access:     Execute Arbitrary Code/Commands -- Remote/Unauthenticated
                   Denial of Service               -- Remote/Unauthenticated
                   Access Confidential Data        -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2019-15139 CVE-2019-13391 CVE-2019-13308
                   CVE-2019-13135 CVE-2019-11598 CVE-2018-18025
                   CVE-2018-16749 CVE-2018-16643 CVE-2017-1000476
                   CVE-2017-1000445 CVE-2017-18273 CVE-2017-18271
                   CVE-2017-18211 CVE-2017-18209 CVE-2017-17914
                   CVE-2017-17682 CVE-2017-15281 CVE-2017-15017
                   CVE-2017-15015 CVE-2017-14741 CVE-2017-14739
                   CVE-2017-14626 CVE-2017-14625 CVE-2017-14624
                   CVE-2017-14532 CVE-2017-14505 CVE-2017-14400
                   CVE-2017-14341 CVE-2017-14249 CVE-2017-14175
                   CVE-2017-14174 CVE-2017-14173 CVE-2017-14172
                   CVE-2017-14060 CVE-2017-13768 CVE-2017-13658
                   CVE-2017-13133 CVE-2017-13061 CVE-2017-12875
                   CVE-2017-12806 CVE-2017-12693 CVE-2017-12692
                   CVE-2017-12691 CVE-2017-12674 CVE-2017-12670
                   CVE-2017-12643 CVE-2017-12563 CVE-2017-12435
                   CVE-2017-12430 CVE-2017-12429 CVE-2017-12140

Reference:         ESB-2020.2252
                   ESB-2020.1142
                   ESB-2020.0269
                   ESB-2019.4338

Original Bulletin: 
   https://www.debian.org/lts/security/2020/dla-2366

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- - -------------------------------------------------------------------------
Debian LTS Advisory DLA-2366-1               debian-lts@lists.debian.org
https://www.debian.org/lts/security/                     Markus Koschany
September 07, 2020                           https://wiki.debian.org/LTS
- - -------------------------------------------------------------------------

Package        : imagemagick
Version        : 8:6.9.7.4+dfsg-11+deb9u10
CVE ID         : CVE-2017-12140 CVE-2017-12429 CVE-2017-12430
        	 CVE-2017-12435 CVE-2017-12563 CVE-2017-12643
                 CVE-2017-12670 CVE-2017-12674 CVE-2017-12691
                 CVE-2017-12692 CVE-2017-12693 CVE-2017-12806
                 CVE-2017-12875 CVE-2017-13061 CVE-2017-13133
                 CVE-2017-13658 CVE-2017-13768 CVE-2017-14060
                 CVE-2017-14172 CVE-2017-14173 CVE-2017-14174
                 CVE-2017-14175 CVE-2017-14249 CVE-2017-14341
                 CVE-2017-14400 CVE-2017-14505 CVE-2017-14532
                 CVE-2017-14624 CVE-2017-14625 CVE-2017-14626
                 CVE-2017-14739 CVE-2017-14741 CVE-2017-15015
                 CVE-2017-15017 CVE-2017-15281 CVE-2017-17682
                 CVE-2017-17914 CVE-2017-18209 CVE-2017-18211
                 CVE-2017-18271 CVE-2017-18273 CVE-2017-1000445
                 CVE-2017-1000476 CVE-2018-16643 CVE-2018-16749
                 CVE-2018-18025 CVE-2019-11598 CVE-2019-13135
                 CVE-2019-13308 CVE-2019-13391 CVE-2019-15139

Debian Bug     : 870020 870019 876105 869727 886281 873059 870504
                 870530 870107 872609 875338 875339 875341 873871
                 873131 875352 878506 875503 875502 876105 876099
                 878546 878545 877354 877355 878524 878547 878548
                 878555 878554 878548 878555 878554 878579 885942
                 886584 928206 941670 931447 932079

Several security vulnerabilities were found in Imagemagick. Various
memory handling problems and cases of missing or incomplete input
sanitizing may result in denial of service, memory or CPU exhaustion,
information disclosure or potentially the execution of arbitrary code
when a malformed image file is processed.

For Debian 9 stretch, these problems have been fixed in version
8:6.9.7.4+dfsg-11+deb9u10.

We recommend that you upgrade your imagemagick packages.

For the detailed security status of imagemagick please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/imagemagick

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
- -----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAl9WpRhfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD
RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQACgkQ2a0UuVE7
UeTl7w//fHuaM3bhEwCf4uMesNeGN0dv+fel55pr9WEZqAq+h8DdkKLefoWX5C9X
wQzKz9zDRZlnMXcdoZZJ3ddeSe1Zq2lZ03iw7ljUrbm6TCbrJw3WV+1Gl3jmRrK9
53VraTj7TnNmlJEx3yKx2CmtBn5dlZv52lfvtFLQHtgOif8NLJ/86C/8rCohKwlH
z3wMrFVLB+hpQgOpV9+Hh3QM4bq34KpPZsa/c7QXlC0yJCTyC/7K45/SsKwTdmzK
Cv4GyqPFoqKXMrK7fDwlfeGbclMz7qMqKBAv8alxKtsa+ayqSUoxfZcVQtU/03DS
ZSsxj/EPizIW+5B88SCyxxOefvumniqFr6Ox846upxqis41cAJ2dM9NXcLyrpV0R
aWzSwDiJjBf2AlzvHJm08LxIjkX6iGqy8z7sSIFnp4U8pi1yAFmovfoVUwAcrOFA
nejYUjzF9z6UyaBriXj42rZFhvC5+BZG9xA323VvAQzIHhGWnz/pmY4t99hh+aYD
VIJ0sjztcebfRYdJyxd2RrmQJE54KJOzz/RhXxYeDJNvOh6g8yX+PCylHyWv0TXD
Ut4AqA7SOp2FqG5vck119v4i+lrfkDbOeA8UHFeIJUUbQ9et4Nz8iIOZ226PrpH1
lghVrx9JlMyUgUl9uorMV8FFhgqH8v8hHD2WZ9CSL8iTsU/kZUA=
=kmXP
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBX1bvQeNLKJtyKPYoAQh8nA//eHeFm/EytgLQ1Qn69y94wETySHjsbJOq
8w7kvJ4ot12qvJeQhHatfcmWXSIQvWlu64JPlh2F9KeHpixXXk8YLVNaFFYyxLbL
j3IEEdmyMl+nKVEDpgC3FxJt0DUMsCODNdx+FyxtmNJcaIaCNwbSJASCHOuB4ufE
CCfms6GdMjBUfA5AzSR1e0o6tgqTJK4ptCNnIabbu/6t4FcgFOTAxIlYwO9Qz0rB
Wl2AEUbcGpeMMoT5Z1jdAvTxPx6TE/xvzSo/XIakSUH3xPGHzoq+VVdzPyLG5Itt
FCUSxBGNRW/wZxDpGDJY7YbzdCURsyx8/9cR24O70QRNSqDe98vMBUF+98ij/9c8
kH14OdTePUXsJ3ggecAcMzU+306E451PHCLW3EjGkATAyLg2o/2BrgCUK8AWpw/1
pzb3whp+FGCl8AuPCXQPumu6iGd3BHpi+ADk2jinDFjsoMfe0gAeGxstjlHLe7HT
vlXrC/zWpKF+V2Sla/2qq3igjT+8nYDHbtzbT7w8zr1ne/nSeDE3wEFdfM9Serix
rhmupNzQoeL/HMjV4F3mXFHd/D8V0a1JrTgtIjHbxMUnXRZXc0hk5cZf2hvxFbKy
nkxP1m0bQi5bi5GkntNW6ZmI1N5NXqISKvZUW3/U8cJJW2ZL6hw+oPTngUbO7WRZ
Wndbh2dIQ+0=
=2EHV
-----END PGP SIGNATURE-----