Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
81b1f32d by Salvatore Bonaccorso at 2026-07-16T06:58:28+02:00
Add imagemagick issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -80,17 +80,31 @@ CVE-2026-61866 (ImageMagick before 7.1.2-26 contains a
memory leak vulnerability
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/0bb3578ee087f3c4f14bbf1d8883ae456fc99092
(7.1.2-26)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/353e2604d1983b6d8ec4c04f4f38bbd4668ba0e1
(6.9.13-51)
CVE-2026-61865 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory
leak in th ...)
- TODO: check
+ - imagemagick 8:7.1.2.26+dfsg1-1
+ NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-j8rh-v2r8-v94x
+ NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/b535126ba5abf23f2693e62ed79f10277d938cf4
(7.1.2-26)
CVE-2026-61864 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory
leak in co ...)
- TODO: check
+ - imagemagick 8:7.1.2.26+dfsg1-1
+ NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7c7m-fpjw-gwcq
+ NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/174275bc1b53e2f23bbff7cd013dc9faa8a99c5a
(7.1.2-26)
CVE-2026-61863 (ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51)
contains a memo ...)
- TODO: check
+ - imagemagick 8:7.1.2.26+dfsg1-1
+ NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6vxp-gfwf-hcr9
+ NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/f3ff3afee942a19e3041568bfa740d48213a3dec
(7.1.2-26)
CVE-2026-61862 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains an
information disc ...)
- TODO: check
+ - imagemagick 8:7.1.2.26+dfsg1-1
+ NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hwf3-r46v-5ggx
+ NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/4079949bae0cde7e683df2e63c40f2e36f52c1b6
(7.1.2-26)
CVE-2026-61860 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a
use-after-free vu ...)
- TODO: check
+ - imagemagick 8:7.1.2.26+dfsg1-1
+ NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6jwg-7q3p-5fqm
+ NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/3fc646a498eecda9163164046189f90dc677ae64
(7.1.2-26)
+ NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/eed471c1286aa27c076348b453b35a2e962967bc
(6.9.13-51)
CVE-2026-61859 (ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51
contains a p ...)
- TODO: check
+ - imagemagick 8:7.1.2.26+dfsg1-1
+ NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vghg-5jrg-2398
+ NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/e047ee2c7b937c1db92302fe3701e2e9c169de27
(7.1.2-26)
+ NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/ffc96e2a4cdc2fcbb9e0f18f082be52e1b4ca012
(6.9.13-51)
CVE-2026-61841
REJECTED
CVE-2026-61839
@@ -124,7 +138,10 @@ CVE-2026-61606
CVE-2026-61605
REJECTED
CVE-2026-61464 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a
heap-based buffer ...)
- TODO: check
+ - imagemagick 8:7.1.2.26+dfsg1-1
+ NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-76q6-2p6h-xjqr
+ NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/378bfc12bf7bbc4d9ab081120873efef935ebd85
(7.1.2-26)
+ NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/d0aa5c9e09e0cf5e400309ca76ae886a980b0555
(6.9.13-51)
CVE-2026-61457 (The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3
contains a ...)
TODO: check
CVE-2026-61453 (Grav v2.0.0 contains a cross-site scripting vulnerability
(fixed in 2. ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/81b1f32daf02cf2364d8e79613c668be403c0634
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/81b1f32daf02cf2364d8e79613c668be403c0634
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits