-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 21 Jul 2026 23:08:38 +0200 Source: imagemagick Architecture: source Version: 8:6.9.11.60+dfsg-1.6+deb12u13 Distribution: bookworm-security Urgency: high Maintainer: ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org> Changed-By: Bastien Roucariès <rouca@debian.org> Changes: imagemagick (8:6.9.11.60+dfsg-1.6+deb12u13) bookworm-security; urgency=high . * Fix CVE-2026-61464: A heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title * Fix CVE-2026-61465: A missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. * Fix CVE-2026-61857: A heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. * Fix CVE-2026-61858: A policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. * Fix CVE-2026-61859: Policy bypass vulnerability in the -script operation due to missing security policy checks. * Fix CVE-2026-61860: A use-after-free vulnerability that occurs when freetype initialization fails. * Fix CVE-2026-61862: When a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). * Fix CVE-2026-61863: A memory leak in the TIFF encoder that occurs when a temporary file cannot be created, * Fix CVE-2026-61864: A memory leak in color transformation to the log colorspace. * Fix CVE-2026-61865 A memory leak in the hough lines operation. * Fix CVE-2026-61866: A memory leak vulnerability in the JNG encoder when a blob cannot be opened. * Fix CVE-2026-61868: A memory leak in the YUV decoder that occurs when opening of the blob fails * Fix CVE-2026-61869: A memory leak in the MIFF encoder that occurs when a memory allocation fails during MIFF image processing, which can lead to denial of service. * Fix CVE-2026-61870: A memory leak vulnerability in the VIFF encoder when memory allocation fails. * Fix CVE-2026-61872: memory leak in the TIFF encoder when an invalid tiff:tile-geometry is specified. Checksums-Sha1: 11e4131ebc278481ec0811c5121593e7c961871f 5134 imagemagick_6.9.11.60+dfsg-1.6+deb12u13.dsc 824a63dce5e54bd8b78077d671d8ab06300a8848 9395144 imagemagick_6.9.11.60+dfsg.orig.tar.xz 16316ce951ae4cac53ccec9026f19e476b823c1c 368032 imagemagick_6.9.11.60+dfsg-1.6+deb12u13.debian.tar.xz c86f88948de6addca6960d18443e71e87d67f7cf 8924 imagemagick_6.9.11.60+dfsg-1.6+deb12u13_source.buildinfo Checksums-Sha256: 5c8b1c18631110ad370fa42a71e2512ebcf2a7b8a5b5554287e04fb259517531 5134 imagemagick_6.9.11.60+dfsg-1.6+deb12u13.dsc 472fb516df842ee9c819ed80099c188463b9e961303511c36ae24d0eaa8959c4 9395144 imagemagick_6.9.11.60+dfsg.orig.tar.xz c90c29b2d46525513b471b1522c6187a25353e3a4101f4a10aa24ac3d741251f 368032 imagemagick_6.9.11.60+dfsg-1.6+deb12u13.debian.tar.xz 18996fd152260aa380fc8feeb1048c824b24dd5a5304fcb8aa693a0319fcff9b 8924 imagemagick_6.9.11.60+dfsg-1.6+deb12u13_source.buildinfo Files: 90e7649d4764699d2103ff9781e14b02 5134 graphics optional imagemagick_6.9.11.60+dfsg-1.6+deb12u13.dsc 8b8f7b82bd1299cf30aa3c488c46a3cd 9395144 graphics optional imagemagick_6.9.11.60+dfsg.orig.tar.xz 857d252b8b4f6b3f7faebe4407f78c5c 368032 graphics optional imagemagick_6.9.11.60+dfsg-1.6+deb12u13.debian.tar.xz 706a83e37aa47facb672f13ce2fa7322 8924 graphics optional imagemagick_6.9.11.60+dfsg-1.6+deb12u13_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmpiIfUACgkQADoaLapB CF9GOA//YK5ZhVmNEsKnfGS7No4eCS2l817zAOIWUg3rQfr1o4+OzhFCt8khRS4l YQ0+gwBZSS+297fg6KEqTIdkcEu4Z4FlM8YqwIAF/VUXduwwvvT1+zp1TdpE9rPS soLitqSbbZkqChi4G8gH34jf/gIFOFP4LGt0Em/CTsW3jffEGj/mJNtu8Ad7p9Rt rT2UO6dyGSE3z4OBYUW47hRUBzrIycYZqahuqGCjFAZ0VntWgrFo7B21s++Zbyfr vvv5n9pSc/63GM8bPol9NCaWneYVknQPTXSSI8SK2swfZrIPZEz33hF8U2aOsqQ8 QwA+l+v0FefiWwq868yO2tsbye/HNwNO6jsoafRza/kfxFMQFc+1rQknt1LNJZ5k 2asobq3u/ACn4pq3wFnbbr/HFexVffJSHvXVMKuSD5rahXvPdjb9F107lyi3CEQt PMlYWq+i8Fp2tFuvjZ0PyUYXpUGnDz6RaBrTSiveN60yKthml/hN9vygBvHGPd1W Kg/1OoifhSSO1rbTyogQuNbRLmL/3XfyC5OTk7tULYqnu0FeV58qF1ZvSR4CpyfP o8KmKtezNxB47p1QvbRcTTD8M/rqFUJpHxSZEwz/3cZ8Ov/0PbLsHj05RBS2QjPr TOPOYAI7KTKMRi/DzItUAztIZoyHJyfWKfCwx9lROTZxAFCoDnA= =ZORq -----END PGP SIGNATURE-----