graphicsmagick (1.4+really1.3.40-4+deb12u1) bookworm-security; urgency=high
authorSalvatore Bonaccorso <carnil@debian.org>
Fri, 11 Apr 2025 20:49:23 +0000 (22:49 +0200)
committerSalvatore Bonaccorso <carnil@debian.org>
Fri, 11 Apr 2025 20:49:23 +0000 (22:49 +0200)
commit090705eb72aae5b4f84642fc9e99d82ab64ff58f
tree263e577f24171bd7d3cc14c47ddf972067d3f401
parentded9e7d1fd34c1706058978e92b506a1bf17979e
parentc59db524136faf9ba2e6e3e03df541be3122de78
graphicsmagick (1.4+really1.3.40-4+deb12u1) bookworm-security; urgency=high

  * Non-maintainer upload by the Security Team.

  [ Carlos Henrique Lima Melara ]
  * d/p/CVE-2025-27795.patch: fix CVE-2025-27795 by adding image dimension
    resource limits. (Closes: #1099955)

  [ Salvatore Bonaccorso ]
  * ReadJXLImage(): pixel_format.num_channels needs to be 2 for grayscale
    matte (CVE-2025-32460)

[dgit import unpatched graphicsmagick 1.4+really1.3.40-4+deb12u1]
62 files changed:
debian/Magick.pm
debian/README.Debian
debian/changelog
debian/control
debian/copyright
debian/graphicsmagick-imagemagick-compat.links
debian/graphicsmagick-libmagick-dev-compat.install
debian/graphicsmagick-libmagick-dev-compat.links
debian/graphicsmagick-libmagick-dev-compat.manpages
debian/graphicsmagick.docs
debian/graphicsmagick.install
debian/graphicsmagick.manpages
debian/graphicsmagick.menu
debian/graphicsmagick.mime
debian/libgraphics-magick-perl.install
debian/libgraphics-magick-perl.manpages
debian/libgraphicsmagick++-q16-12.install
debian/libgraphicsmagick++-q16-12.symbols.32bit.in
debian/libgraphicsmagick++-q16-12.symbols.64bit.in
debian/libgraphicsmagick++-q16-12.symbols.alpha.disabled
debian/libgraphicsmagick++-q16-12.symbols.amd64.disabled
debian/libgraphicsmagick++-q16-12.symbols.arm.disabled
debian/libgraphicsmagick++-q16-12.symbols.armel.disabled
debian/libgraphicsmagick++-q16-12.symbols.common.in
debian/libgraphicsmagick++-q16-12.symbols.disabled
debian/libgraphicsmagick++-q16-12.symbols.hppa.disabled
debian/libgraphicsmagick++-q16-12.symbols.hppa.in
debian/libgraphicsmagick++-q16-12.symbols.i386.disabled
debian/libgraphicsmagick++-q16-12.symbols.ia64.disabled
debian/libgraphicsmagick++-q16-12.symbols.m68k.disabled
debian/libgraphicsmagick++-q16-12.symbols.mips.disabled
debian/libgraphicsmagick++-q16-12.symbols.mipsel.disabled
debian/libgraphicsmagick++-q16-12.symbols.powerpc.disabled
debian/libgraphicsmagick++-q16-12.symbols.s390.disabled
debian/libgraphicsmagick++-q16-12.symbols.sparc.disabled
debian/libgraphicsmagick++1-dev.dirs
debian/libgraphicsmagick++1-dev.install
debian/libgraphicsmagick++1-dev.links
debian/libgraphicsmagick++1-dev.manpages
debian/libgraphicsmagick-q16-3.install
debian/libgraphicsmagick-q16-3.symbols
debian/libgraphicsmagick1-dev.dirs
debian/libgraphicsmagick1-dev.install
debian/libgraphicsmagick1-dev.links
debian/libgraphicsmagick1-dev.manpages
debian/patches/CVE-2025-27795.patch
debian/patches/CVE-2025-32460.patch
debian/patches/eliminate_memory_leak_when_handling_EXIFOrientation.patch
debian/patches/fix_bounds_issue_when_concatenating_string.patch
debian/patches/link-demos.diff
debian/patches/semaphore_O0_ppc64el.patch
debian/patches/series
debian/reference-new/PerlMagick/t/reference/ttf/annotate.miff.uu
debian/reference-new/PerlMagick/t/reference/ttf/label.miff.uu
debian/reference-new/PerlMagick/t/reference/ttf/read.miff.uu
debian/reference-new/PerlMagick/t/reference/wmf/ski.miff.uu
debian/rules
debian/source/format
debian/source/lintian-overrides
debian/upstream/metadata
debian/upstream/signing-key.asc
debian/watch