#1142554 trixie-pu: package imagemagick/8:7.1.1.43+dfsg1-1+deb13u12

#1142554#5
Date:
2026-07-21 17:10:50 UTC
From:
To:
[ Reason ]
About 22 low impact CVEs

[ Impact ]
CVE are not closed

[ Tests ]
Automatic

[ Risks ]
Low

[ Checklist ]
  [X] *all* changes are documented in the d/changelog
  [X] I reviewed all changes and I approve them
  [X] attach debdiff against the package in (old)stable
  [X] the issue is verified as fixed in unstable

[ Changes ]
See changelog all CVE are closed

[ Other info ]
security team and myself think it is a good idea to upload quickly, in order to
not have a lot of CVE piled up.

Debusine: https://debusine.debian.net/debian/developers/work-request/932300/

#1142554#12
Date:
2026-07-21 19:22:30 UTC
From:
To:
Hi Bastien,

I believe this one should be CVE-2026-61867.

Regards,
Salvatore

#1142554#17
Date:
2026-07-21 19:46:08 UTC
From:
To:
Le mardi 21 juillet 2026, 21:22:30 heure d’été d’Europe centrale Salvatore Bonaccorso a écrit :

Yes fixed thank

#1142554#22
Date:
2026-07-24 14:24:41 UTC
From:
To:
Hi,

This is unusually large but it's well organised enough that I can read it.
Please go ahead with fixed CVE ref and target trixie.

Thanks,

#1142554#29
Date:
2026-08-27 14:21:57 UTC
From:
To:
Hi

I have upload to PU

rouca

#1142554#34
Date:
2026-09-04 11:25:53 UTC
From:
To:
package release.debian.org
tags 1142554 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: imagemagick
Version: 7.1.1.43+dfsg1-1+deb13u12

Explanation: fix buffer overflow isses [CVE-2026-56362 CVE-2026-56372 CVE-2026-56374 CVE-2026-61464]; fix memory leak issues [CVE-2026-56366 CVE-2026-56375 CVE-2026-61863 CVE-2026-61864 CVE-2026-61865 CVE-2026-61866 CVE-2026-61867 CVE-2026-61868 CVE-2026-61869 CVE-2026-61870 CVE-2026-61871 CVE-2026-61872]; fix use-after-free issues [CVE-2026-56373 CVE-2026-61857 CVE-2026-61860 CVE-2026-61861]; fix denial of service issue [CVE-2026-61465]; fix policy bypass issues [CVE-2026-61858 CVE-2026-61859]; fix information disclosure issue [CVE-2026-61862]

#1142554#39
Date:
2026-09-04 11:25:53 UTC
From:
To:
package release.debian.org
tags 1142554 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: imagemagick
Version: 7.1.1.43+dfsg1-1+deb13u12

Explanation: fix buffer overflow isses [CVE-2026-56362 CVE-2026-56372 CVE-2026-56374 CVE-2026-61464]; fix memory leak issues [CVE-2026-56366 CVE-2026-56375 CVE-2026-61863 CVE-2026-61864 CVE-2026-61865 CVE-2026-61866 CVE-2026-61867 CVE-2026-61868 CVE-2026-61869 CVE-2026-61870 CVE-2026-61871 CVE-2026-61872]; fix use-after-free issues [CVE-2026-56373 CVE-2026-61857 CVE-2026-61860 CVE-2026-61861]; fix denial of service issue [CVE-2026-61465]; fix policy bypass issues [CVE-2026-61858 CVE-2026-61859]; fix information disclosure issue [CVE-2026-61862]

#1142554#44
Date:
2026-09-12 08:05:41 UTC
From:
To:
This update was released as part of 13.7.