-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 29 Jan 2020 19:03:02 +0100 Source: graphicsmagick Binary: graphicsmagick graphicsmagick-dbg graphicsmagick-imagemagick-compat graphicsmagick-libmagick-dev-compat libgraphics-magick-perl libgraphicsmagick++-q16-12 libgraphicsmagick++1-dev libgraphicsmagick-q16-3 libgraphicsmagick1-dev Architecture: source amd64 all Version: 1.4~hg15978-1+deb10u1 Distribution: buster-security Urgency: medium Maintainer: Laszlo Boszormenyi (GCS) <gcs@debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Description: graphicsmagick - collection of image processing tools graphicsmagick-dbg - format-independent image processing - debugging symbols graphicsmagick-imagemagick-compat - image processing tools providing ImageMagick interface graphicsmagick-libmagick-dev-compat - image processing libraries providing ImageMagick interface libgraphics-magick-perl - format-independent image processing - perl interface libgraphicsmagick++-q16-12 - format-independent image processing - C++ shared library libgraphicsmagick++1-dev - format-independent image processing - C++ development files libgraphicsmagick-q16-3 - format-independent image processing - C shared library libgraphicsmagick1-dev - format-independent image processing - C development files Changes: graphicsmagick (1.4~hg15978-1+deb10u1) unstable; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2019-19953 heap-based buffer over-read in the function EncodeImage * CVE-2019-19951 heap-based buffer overflow in the function ImportRLEPixels * CVE-2019-19950 use-after-free in ThrowException and ThrowLoggedException Checksums-Sha1: 1dff6fbd87d31e6102bcf5cb13a14b9015bd4df5 3046 graphicsmagick_1.4~hg15978-1+deb10u1.dsc a76df5c3073c48b7bcff4d2c76550bcc6ed8c502 8879584 graphicsmagick_1.4~hg15978.orig.tar.xz 6db503feeda97cfe0e379f4bfcc98d64dd225cb0 147116 graphicsmagick_1.4~hg15978-1+deb10u1.debian.tar.xz 6aa4e7ee79aea23a1a84b821e1ac3e69fb34d718 4129696 graphicsmagick-dbg_1.4~hg15978-1+deb10u1_amd64.deb 5efddba1248a74692da8cdcd5751bb288778bdbd 32296 graphicsmagick-imagemagick-compat_1.4~hg15978-1+deb10u1_all.deb 89d2a6c87d83a3b77a9de55a68f2d5b99f789e48 35728 graphicsmagick-libmagick-dev-compat_1.4~hg15978-1+deb10u1_all.deb 6d0e77da574418db20a608bf866bad688204705e 11643 graphicsmagick_1.4~hg15978-1+deb10u1_amd64.buildinfo 04abc8ca4f0931ad013730f586d86a7c2024f3d6 985600 graphicsmagick_1.4~hg15978-1+deb10u1_amd64.deb 24589c8d5cbbdb08d99f82b56d056dc63efb580a 80108 libgraphics-magick-perl_1.4~hg15978-1+deb10u1_amd64.deb be8dd724951a80dff19b7fea7c34506f06f8b6f1 131624 libgraphicsmagick++-q16-12_1.4~hg15978-1+deb10u1_amd64.deb 5863b88ad1983387d6793cc539db31944d71174f 319512 libgraphicsmagick++1-dev_1.4~hg15978-1+deb10u1_amd64.deb 5eb2fd1f913e12d8055a69f9a3a359ef8945b1ef 1159084 libgraphicsmagick-q16-3_1.4~hg15978-1+deb10u1_amd64.deb 67e1050c669b6514bc02b132eb724a4e723846b3 1395696 libgraphicsmagick1-dev_1.4~hg15978-1+deb10u1_amd64.deb Checksums-Sha256: 364c91f4f340bb5b2a5682413f3b0d456ec74258b18905376a3814c165a5c03e 3046 graphicsmagick_1.4~hg15978-1+deb10u1.dsc 718f0de294aa3263c4ec41c76abd199ce9915f2dde844f7ea7202a80c04620c6 8879584 graphicsmagick_1.4~hg15978.orig.tar.xz d55a0feafb5278245c726f20520c32d7716f35542a34df3f6d0379ae832df94a 147116 graphicsmagick_1.4~hg15978-1+deb10u1.debian.tar.xz cb4f130f8d029a20c985dfbbe99b5f83c436b429446e1cc168c632d3c64a9edf 4129696 graphicsmagick-dbg_1.4~hg15978-1+deb10u1_amd64.deb 52574e4e1622dd97c7f9553e829f0008114e41c4c0c718d646e57b8675124f27 32296 graphicsmagick-imagemagick-compat_1.4~hg15978-1+deb10u1_all.deb e3bbae96cca150943fc6ac07ef820106200dbae87dc37d06709b69a9e28410ee 35728 graphicsmagick-libmagick-dev-compat_1.4~hg15978-1+deb10u1_all.deb 4a6c45f4bac6e02e1d0ca1a8b4d70805173a82fce65b76075fac29ff47d8ba4f 11643 graphicsmagick_1.4~hg15978-1+deb10u1_amd64.buildinfo 4ca540e6239b1cf01ec695072e8431b4de0c8d8bec57a87a2a3abc69a7aab8c5 985600 graphicsmagick_1.4~hg15978-1+deb10u1_amd64.deb c866e5a8e25e54ae6e04da44b551ad605d433d64f32182e80fba4fafa2f2df74 80108 libgraphics-magick-perl_1.4~hg15978-1+deb10u1_amd64.deb ddbdfdf5a901ba42bd176e5f9ab95eda6df37dc027352dfcef38f2beaa543f1b 131624 libgraphicsmagick++-q16-12_1.4~hg15978-1+deb10u1_amd64.deb b26be79a219e4c1d76e9b6d0d5b04184892db631d13966e0f55261896a87882e 319512 libgraphicsmagick++1-dev_1.4~hg15978-1+deb10u1_amd64.deb 94ee16104d5bd3cf4b7785789a78ff76a1e16b9e689c3f90bb0cbe6228dd544b 1159084 libgraphicsmagick-q16-3_1.4~hg15978-1+deb10u1_amd64.deb 69b287583e675d59c350703cff7026516bd516f07e087ed23b1f77e387ff1047 1395696 libgraphicsmagick1-dev_1.4~hg15978-1+deb10u1_amd64.deb Files: 1ecbd43111d2b309e2349cc8c369168b 3046 graphics optional graphicsmagick_1.4~hg15978-1+deb10u1.dsc 66b9c21df93a266c7a88211025a4fb76 8879584 graphics optional graphicsmagick_1.4~hg15978.orig.tar.xz 5a7e06202bc08ddd39ca2a423808f2df 147116 graphics optional graphicsmagick_1.4~hg15978-1+deb10u1.debian.tar.xz 65128e7f2dcdb49384f866507fab57cc 4129696 debug optional graphicsmagick-dbg_1.4~hg15978-1+deb10u1_amd64.deb a98a43a624da8eb760f68a9b586ad837 32296 graphics optional graphicsmagick-imagemagick-compat_1.4~hg15978-1+deb10u1_all.deb b6acae5b9fc17009da5292d933009505 35728 graphics optional graphicsmagick-libmagick-dev-compat_1.4~hg15978-1+deb10u1_all.deb 52f9065acb13a1a8ac0a78ae3cedfaf7 11643 graphics optional graphicsmagick_1.4~hg15978-1+deb10u1_amd64.buildinfo b62bb5ea456c1ea4d7e921d910a482f7 985600 graphics optional graphicsmagick_1.4~hg15978-1+deb10u1_amd64.deb bbabc7e6a2e374eb0c325e8268045a87 80108 perl optional libgraphics-magick-perl_1.4~hg15978-1+deb10u1_amd64.deb 95ea91253c7efe752f8dc600751cf106 131624 libs optional libgraphicsmagick++-q16-12_1.4~hg15978-1+deb10u1_amd64.deb 49feddd8cc649eb2372b2d9001fc7b65 319512 libdevel optional libgraphicsmagick++1-dev_1.4~hg15978-1+deb10u1_amd64.deb 37b6353423e0ab85711bf993b6f47685 1159084 libs optional libgraphicsmagick-q16-3_1.4~hg15978-1+deb10u1_amd64.deb 99d585357375bc82c0708e6773986250 1395696 libdevel optional libgraphicsmagick1-dev_1.4~hg15978-1+deb10u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAl5mWXRfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYR8jREACnjmStxLco+G2Effh1d76062vuMKnz kHwDA2+JMkIXF2iF6ZbKic+qmVu9TSVQzr991RmTvr2QkDzNqCpdZBOl/CqTOQYf rz7hV+cVEGms+CLiguRhjqTIiN6vfQpkgIjtb/6XzDscZXpLpmeQ719CkBUj0a1/ NgP0IIbotjxOfZGvlVWSIJ2kl9rEPXdHQkh65zLFn+pZrURjewGDUlff/Xj4A/zX 5R0/ndDCi5B7CI1wHpFhIGDYaIiclGZ3rC5fdqGf0Srjonl8PCAvYZIDHUQ77sai fjf+LpDwolLzmb9FamsaFtdeZBoYpkOxOUn6v/m4KNuhC1k6ZOJuKnpYxPL04Nx7 DYHBYhfHrimeCw9G6FFEMayxHM6WQ9vLLNHrsWD725ShxZJTA/35uZ68nUEp9nUi 9m+g/JigWCgZzxyWLIoI11DVIsStDnMbxh7h5NPylQr93K6NIsDWzfMzyTmyVb29 A3mFTchoonKP+v7nfFAGKzqFVwh9/FHl88GCJmmpnLibsxbHBvOrlYxNAOumOS1V V0t5qqk/q91cv7KUsggtZgjexhUOS3L4yTw2L2O+AUtHlSAzkW2usmhzvFjfsyK9 VajS2ypcYSWU+jUDrqXKXdIhnUIFEmOIwOp8Nj3m195AvLZ3Ky6fLz75I5rnH8q8 Ee1PIQdjOKi3nA== =U4Be -----END PGP SIGNATURE-----