-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 28 Oct 2025 17:06:16 +0100 Source: imagemagick Architecture: source Version: 8:7.1.2.8+dfsg1-1 Distribution: unstable Urgency: medium Maintainer: ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org> Changed-By: Bastien Roucariès <rouca@debian.org> Changes: imagemagick (8:7.1.2.8+dfsg1-1) unstable; urgency=medium . * New upstream version * Fix CVE-2025-62594: ImageMagick is vulnerable to denial-of-service due to unsigned integer underflow and division-by-zero in the CLAHEImage function. When tile width or height is zero, unsigned underflow occurs in pointer arithmetic, leading to out-of-bounds memory access, and division-by-zero causes immediate crashes. Checksums-Sha1: 8a6174c67443cebc30731373849711a90f4c7a71 5097 imagemagick_7.1.2.8+dfsg1-1.dsc 5a0d91a8869721f92e4568f9c7ed2ef3fee6b2c8 10517668 imagemagick_7.1.2.8+dfsg1.orig.tar.xz c56b58b0389e904c3bc848117fc26d55e78ff7ae 267352 imagemagick_7.1.2.8+dfsg1-1.debian.tar.xz 46344aea5c4da3ae27801ddadb739b84c1e29caa 8076 imagemagick_7.1.2.8+dfsg1-1_source.buildinfo Checksums-Sha256: f1d031b0175a0e747f1c61a3c4cb03911b18cdc466e24203b0dddf014c5bf0cb 5097 imagemagick_7.1.2.8+dfsg1-1.dsc ad5e43fb2e7ed069916f4716218aba6e2bb043e0b2cf99bee8d4cc30ce12ee9f 10517668 imagemagick_7.1.2.8+dfsg1.orig.tar.xz 339bb1820572292cff0eb7b18f117f8642d01e4ea9d30b8466bef924534afb15 267352 imagemagick_7.1.2.8+dfsg1-1.debian.tar.xz c33b395370e664df00eb08adfd44403b3ae641680bce60d7dbf05450874add2e 8076 imagemagick_7.1.2.8+dfsg1-1_source.buildinfo Files: e0fc011e4511dd8b2fd27bd72c008871 5097 graphics optional imagemagick_7.1.2.8+dfsg1-1.dsc 81c36e65f719e105604128800a2bc7c6 10517668 graphics optional imagemagick_7.1.2.8+dfsg1.orig.tar.xz 4aa8d55105d29fc4b3b2d3e597b80d4d 267352 graphics optional imagemagick_7.1.2.8+dfsg1-1.debian.tar.xz c428a80d89910ed376fbd8e0dce3e0f0 8076 graphics optional imagemagick_7.1.2.8+dfsg1-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmkBHa4ACgkQADoaLapB CF/3sA/7BL73I6ASTr6itKTnWcizvI/xh2KDLWEGpZTW4NNny4E25PnkQJfy96GZ DfsbHzY9Gj/VgcmRRSZ6CSK4hdSknYpPsxX1DSzZjUZFWYcCCluRf/LnqI9ZfDgN 2x2wxoTtfETAK9vnzT6DNcx6k5rivkWi9s6WfB2XDblhjc1hYZ/VtB47JcJDIJJz XDcM3ObLHjPt5L+R0LTB8qrxJNNeI3eBhFBCtXnWI+SSyG04G/o0Sed2JDe4mIBK GBjN7laEgAWdA0Deo5CF3uFZxmWtfW/CMKM0Z0yyGkyGOPScDUMoriGIISnXEKyu W0Kx97exkai6Jdj0XxxOF0JtqIFskwFRssHBqqh3Et9E5g+rwGBcbfVHJ30DZjI2 GDbePZUA5tJDFbzdeQCnsWdiv/1NwU8AkZIGMWEBlR29TpQdbr8IiNfvzboO8nB+ NU2IGqIZ3eMfvPrjDfYOwygdsgYOmoq/W8T0Dbs8HbOUX8tjM6mwYroU6627wRlx 6JuqTGsxVepiP0UKhjz8P87oYYz8guBVyoj79sopCRptuhxgcKGDvFlToyWQySnF J73Lk6rFxnCAecRhf06ANKjWVxwzbDkwUGSJy1te2f3jMP5SMDx00PJv8s4CQe3E vAAJcTl/nDpPlOd74DGXNsBkGeUe9cBh/+vuybMDFIvYFDsZf18= =xRBL -----END PGP SIGNATURE-----