Errata overview
Errata ID 55
Date 2017-06-28
Source package imagemagick
Fixed in version 8:6.8.9.9-5+deb8u9
Description
This update addresses the following issues:
* Undefined behavior in rle (CVE-2017-7606)
* Infinite loop due to rounding error (CVE-2017-7619)
* memory leak in sgi (CVE-2017-7941)
* memory leak in svg (CVE-2017-7943)
* The ReadAAIImage function in aai.c allows attackers to cause a denial of
  service (memory leak) via a crafted file (CVE-2017-8343)
* Fix DOS in PCX file coders (CVE-2017-8344)
* The ReadMNGImage function in png.c allows attackers to cause a denial of
  service (memory leak) via a crafted file (CVE-2017-8345)
* The ReadDCMImage function in dcm.c allows attackers to cause a denial of
  service (memory leak) via a crafted file (CVE-2017-8346)
* Fix DOS in EXR file coders (CVE-2017-8347)
* Fix DOS in MAT file coders (CVE-2017-8348)
* Fix DOS in SWF file coders (CVE-2017-8349)
* Fix DOS in png file coders (CVE-2017-8350)
* Fix DOS in pcd file coders (CVE-2017-8351)
* Fix DOS in xwd file coders (CVE-2017-8352)
* Fix DOS in pict file coders (CVE-2017-8353)
* Fix DOS in bmp file coders (CVE-2017-8354)
* Fix DOS in mtv file coders (CVE-2017-8355)
* Fix DOS in sun file coders (CVE-2017-8356)
* Fix DOS in ept file coders (CVE-2017-8357)
* Fix DOS in icon file coders (CVE-2017-8765)
* Fix DOS in bmp file coders (CVE-2017-8830)
* Check for EOF conditions for RLE image format (CVE-2017-9144)
* A crafted file revealed an assertion failure in blob.c (CVE-2017-9142)
* A crafted file revealed an assertion failure in profile.c (CVE-2017-9142)
* Specially crafted arts file could lead to memory leak (CVE-2017-9143)
* Fix an information leak due to the use of uninitialized memory in RLE
  decoder (CVE-2017-9098)
* Assertion failure in TGA coder (CVE-2017-6498)
* Out of bound in sun file coder (CVE-2017-6500)
* Memory leak in libmagick++ library (CVE-2017-6499)
* Missing null pointer check in xcf coder and psd coder (CVE-2017-6501,
  CVE-2017-6497)
* Fix a memory leak in options handler.
* Fix a regression in jessie, Fix artefacts running -sharpen on CMYK images
Additional notes
CVE ID CVE-2017-7606
CVE-2017-7619
CVE-2017-7941
CVE-2017-7943
CVE-2017-8343
CVE-2017-8344
CVE-2017-8345
CVE-2017-8346
CVE-2017-8347
CVE-2017-8348
CVE-2017-8349
CVE-2017-8350
CVE-2017-8351
CVE-2017-8352
CVE-2017-8353
CVE-2017-8354
CVE-2017-8355
CVE-2017-8356
CVE-2017-8357
CVE-2017-8765
CVE-2017-8830
CVE-2017-9144
CVE-2017-9142
CVE-2017-9143
CVE-2017-9098
CVE-2017-6498
CVE-2017-6500
CVE-2017-6499
CVE-2017-6501
CVE-2017-6497
UCS Bug number #44403