-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 10 Oct 2017 17:57:27 +1100 Source: graphicsmagick Binary: graphicsmagick libgraphicsmagick3 libgraphicsmagick1-dev libgraphicsmagick++3 libgraphicsmagick++1-dev libgraphics-magick-perl graphicsmagick-imagemagick-compat graphicsmagick-libmagick-dev-compat graphicsmagick-dbg Architecture: source amd64 all Version: 1.3.16-1.1+deb7u10 Distribution: wheezy-security Urgency: high Maintainer: Daniel Kobras <kobras@debian.org> Changed-By: Brian May <bam@debian.org> Description: graphicsmagick - collection of image processing tools graphicsmagick-dbg - format-independent image processing - debugging symbols graphicsmagick-imagemagick-compat - image processing tools providing ImageMagick interface graphicsmagick-libmagick-dev-compat - image processing libraries providing ImageMagick interface libgraphics-magick-perl - format-independent image processing - perl interface libgraphicsmagick++1-dev - format-independent image processing - C++ development files libgraphicsmagick++3 - format-independent image processing - C++ shared library libgraphicsmagick1-dev - format-independent image processing - C development files libgraphicsmagick3 - format-independent image processing - C shared library Changes: graphicsmagick (1.3.16-1.1+deb7u10) wheezy-security; urgency=high . * Non-maintainer upload by the LTS Team. * Fix CVE-2017-14103: The ReadJNGImage and ReadOneJNGImage functions in coders/png.c did not properly manage image pointers after certain error conditions. * Fix CVE-2017-14314: heap-based buffer over-read in DrawDashPolygon() . * Fix CVE-2017-14504: NULL pointer dereference triggered by malformed file. * Fix CVE-2017-14733: Ensure we detect alpha images with too few colors. * Fix CVE-2017-14994: DCM_ReadNonNativeImages() can produce image list with no frames, resulting in null image pointer. * Fix CVE-2017-14997: unsigned underflow leading to astonishingly large allocation request. Checksums-Sha1: b3f0f21f80d668f33e8ed77c42d8cb7102ede511 2686 graphicsmagick_1.3.16-1.1+deb7u10.dsc f2ec0392d7a7d5cbe0d5bdff2931edbacedd73e9 8736761 graphicsmagick_1.3.16.orig.tar.gz e3533915f279a72308144cc40d95d4268b070da3 198249 graphicsmagick_1.3.16-1.1+deb7u10.debian.tar.gz 1a01ead3adff128418be62e771addadd82699f12 1034612 graphicsmagick_1.3.16-1.1+deb7u10_amd64.deb a2d8f7737d004ed53bceb8685602077374ae7262 1324250 libgraphicsmagick3_1.3.16-1.1+deb7u10_amd64.deb 2efcd0d4c5f8b43d9d1eef973047e9824a9b18e3 1822836 libgraphicsmagick1-dev_1.3.16-1.1+deb7u10_amd64.deb 4c5bbd57073ef1da04a8cae0ca42a89e899b4905 154678 libgraphicsmagick++3_1.3.16-1.1+deb7u10_amd64.deb e1d1f9b293b249ea9c7078e34ee02a1d391b15cb 410866 libgraphicsmagick++1-dev_1.3.16-1.1+deb7u10_amd64.deb bb82c88eca4330b67dcfa23c6edb0b0caad4526b 83436 libgraphics-magick-perl_1.3.16-1.1+deb7u10_amd64.deb 790b0db8917b9fb0d840abef9530a9c2ae627559 3270206 graphicsmagick-dbg_1.3.16-1.1+deb7u10_amd64.deb e35712a8b3eb9f9cabf8f725146a2e996fdd636a 18674 graphicsmagick-imagemagick-compat_1.3.16-1.1+deb7u10_all.deb 0eee8b2f448d9170e8419e070dbe6cc9cad11b47 22228 graphicsmagick-libmagick-dev-compat_1.3.16-1.1+deb7u10_all.deb Checksums-Sha256: 2d0d2c265a502fb21631f18a3a71951ccde3a2acac9da91767434b2deecca307 2686 graphicsmagick_1.3.16-1.1+deb7u10.dsc ae2229370926dea6c2423cc1adaf551d33f38102677332294439365aaac1514b 8736761 graphicsmagick_1.3.16.orig.tar.gz ad8747b1768312ecce3ec335ad093bf25d33d4193465c0988f3896df6e4a2d30 198249 graphicsmagick_1.3.16-1.1+deb7u10.debian.tar.gz 1b2990c052a9b8f49d9f6af64564329bbac3e39cdf6e407695cc4b29e9b58b59 1034612 graphicsmagick_1.3.16-1.1+deb7u10_amd64.deb cd9566db3b7e68d787baae7ceea335d12399b77338d736c04f98811729335fd1 1324250 libgraphicsmagick3_1.3.16-1.1+deb7u10_amd64.deb ecf617ff5d5f2c151cfb4c17f6d6e312afe9bf346fb722f3d07eeb67dc7dbddc 1822836 libgraphicsmagick1-dev_1.3.16-1.1+deb7u10_amd64.deb 984a1f67c1c56ca14b82e7f08fdaf868e0c46e58daaa8ec45a7a561884f72999 154678 libgraphicsmagick++3_1.3.16-1.1+deb7u10_amd64.deb e24a195090d1f45e91bfe0f28eae3cffcbd1ee587e0819f6af882fca782e99ec 410866 libgraphicsmagick++1-dev_1.3.16-1.1+deb7u10_amd64.deb eda4efd41fe44fa9f0f6d591fcf7b84c74ada8427d165601160c0ff667fba40d 83436 libgraphics-magick-perl_1.3.16-1.1+deb7u10_amd64.deb 1bf44bc81ff895ae58bece36484e7f16b7598ab29530b162b97298a2006b04ef 3270206 graphicsmagick-dbg_1.3.16-1.1+deb7u10_amd64.deb 661a448bb14b60d4d93af3147a464fe1de9f784ec7bdc7221af0c33ba6ea68ab 18674 graphicsmagick-imagemagick-compat_1.3.16-1.1+deb7u10_all.deb 4e11c628270b7badcf99050ed6cb3327b72646ea50a288f96d616bdfb3e1848d 22228 graphicsmagick-libmagick-dev-compat_1.3.16-1.1+deb7u10_all.deb Files: 5d954dfe73d94199637115f7950039d8 2686 graphics optional graphicsmagick_1.3.16-1.1+deb7u10.dsc 66a4b9c7af6165b5d293fed6ebe04e36 8736761 graphics optional graphicsmagick_1.3.16.orig.tar.gz bed4cd314cc38ede112c5a9dadfa925f 198249 graphics optional graphicsmagick_1.3.16-1.1+deb7u10.debian.tar.gz 5602d9eb84cd3b0455eb6ac49507ae56 1034612 graphics optional graphicsmagick_1.3.16-1.1+deb7u10_amd64.deb e6ec0f18032e6a8f2d39aab4855e9a0e 1324250 libs optional libgraphicsmagick3_1.3.16-1.1+deb7u10_amd64.deb 99cf11b1672a5a8aaab154f783fd5e6a 1822836 libdevel optional libgraphicsmagick1-dev_1.3.16-1.1+deb7u10_amd64.deb da0cc9940401b658c041743b4fdcf8b0 154678 libs optional libgraphicsmagick++3_1.3.16-1.1+deb7u10_amd64.deb 30d29945d22bca0d1b6fdcdc71145bb9 410866 libdevel optional libgraphicsmagick++1-dev_1.3.16-1.1+deb7u10_amd64.deb f0e3c9f23f43839506d6b57d7b552cc7 83436 perl optional libgraphics-magick-perl_1.3.16-1.1+deb7u10_amd64.deb 9c904edea11b63706ca6a9b1ad9297fb 3270206 debug extra graphicsmagick-dbg_1.3.16-1.1+deb7u10_amd64.deb c88d1111118c16c0df8ab8accfed88d4 18674 graphics extra graphicsmagick-imagemagick-compat_1.3.16-1.1+deb7u10_all.deb 833cf2bfb48df810ca082dc838fe8485 22228 graphics extra graphicsmagick-libmagick-dev-compat_1.3.16-1.1+deb7u10_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEE1jZRJqkttWDGJ6ztF4RXf4EfbqwFAlndtxAACgkQF4RXf4Ef bqxwgQ/8CCb9+IveKh5QPhZbbqlugnL8FRi6AH2n06juIiDUyJWT8dliMhT5rUQl ov1c5HPQ5LuofqRbfIIdQ8Xf/sJ2IlFXClZt7sEU7XVtv5HxRHX9FTXAGIZXPlPu lMCC8acGq+Ek6CjGj2Rg69vavjMBVTtFn7FMDgoJ9xgkYCKzkdbuWfS3yo4bAjYd c1DXCCc52IK4lYaNdP9RH0JHlxFE4M2l4jZILnbDYhAzAyKB5dc8ZfO15rEHOOJJ qLxSWiW8ke0DXUkGy3dxK7ZAGQ8PWpc644a9V4ucqyaT2yjfdNIq7zupWlWuywhN SDE9xR4KliO2ILV8GZlPzXqOTGriP8dQLPbK8ZvRZ7H44qsknRsYVI4zdCiboG5C 6vzkUCZFylQXce+ffD/NOM264gBjvjHzzU0+TpyjVvp8hC6VfMbO86qN7e7RL7Sw QxbquluSJY/Mv/hlgDcMEmfJDsp+xMUH+WqOMD11xCHlEqffZc23OXPa5xla1mq0 /sy+s0AFtIzOyP/ExKM1FzHxqdUSc7ba85rBm4HbvCqT/uO7RgD4OGJoXYOl1PvU S33xS9DCcY3/1rk8j3J1PgiwoxtCmBieV9u3v1VlWYA+mIxNT+iiH9/3eqmz1A/o qfN6gbvZcGULe5Rhd+Z27Dox//kKD347dC4MGrmJ1Yer6N1AzIE= =St80 -----END PGP SIGNATURE-----