Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
24f97375 by Salvatore Bonaccorso at 2026-07-17T21:26:55+02:00
Triage imagemagick for trixie
All of the currently open issues in trixie seem fairly low severity so
they IMHO can be included in a future update or a point release.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1173,56 +1173,68 @@ CVE-2026-61873 (Grav before 9.1.8 contains an arbitrary
file write vulnerability
NOT-FOR-US: Grav CMS
CVE-2026-61872 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory
leak in th ...)
- imagemagick 8:7.1.2.26+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h5r4-w88w-7ccr
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/ed143b98d72bba764b010eb822464f2a12b24ff1
(7.1.2-26)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/3f0595f0778201326163253bfdc8bce9a4bbadf6
(6.9.13-51)
CVE-2026-61871 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory
leak in th ...)
- imagemagick 8:7.1.2.26+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h58x-r7f7-rh84
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/b237a4fa9cbffcb11ee579d386fd37c570d5dffe
(7.1.2-26)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/e4b68bfb6a9541a9c3a4af81a21bf0c253661083
(6.9.13-51)
CVE-2026-61869 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory
leak in th ...)
- imagemagick 8:7.1.2.26+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r628-69v2-2f9c
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/b2dc602e175ee07b0794f3e31f1a29ae6b7267d1
(7.1.2-26)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/ca6c9da425880fde937da41d59666dedf5e719e1
(6.9.13-51)
CVE-2026-61868 (ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51
contains a memo ...)
- imagemagick 8:7.1.2.26+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h7f2-f9cc-h2gv
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/808506dc4d0cbf3972ce0d57544a06209b65009c
(7.1.2-26)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/875bd8912b3b54a58e09c14085cf2b14a478a86b
(6.9.13-51)
CVE-2026-61867 (ImageMagick before 7.1.2-26 contains a memory leak
vulnerability in th ...)
- imagemagick 8:7.1.2.26+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-jfq9-q63x-rc63
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/f34065ecd9512df16cb10083c8b4b46b5cd09b30
(7.1.2-26)
CVE-2026-61866 (ImageMagick before 7.1.2-26 contains a memory leak
vulnerability in th ...)
- imagemagick 8:7.1.2.26+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-99w9-hv66-rfv7
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/0bb3578ee087f3c4f14bbf1d8883ae456fc99092
(7.1.2-26)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/353e2604d1983b6d8ec4c04f4f38bbd4668ba0e1
(6.9.13-51)
CVE-2026-61865 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory
leak in th ...)
- imagemagick 8:7.1.2.26+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-j8rh-v2r8-v94x
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/b535126ba5abf23f2693e62ed79f10277d938cf4
(7.1.2-26)
CVE-2026-61864 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory
leak in co ...)
- imagemagick 8:7.1.2.26+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7c7m-fpjw-gwcq
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/174275bc1b53e2f23bbff7cd013dc9faa8a99c5a
(7.1.2-26)
CVE-2026-61863 (ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51)
contains a memo ...)
- imagemagick 8:7.1.2.26+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6vxp-gfwf-hcr9
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/f3ff3afee942a19e3041568bfa740d48213a3dec
(7.1.2-26)
CVE-2026-61862 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains an
information disc ...)
- imagemagick 8:7.1.2.26+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hwf3-r46v-5ggx
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/4079949bae0cde7e683df2e63c40f2e36f52c1b6
(7.1.2-26)
CVE-2026-61860 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a
use-after-free vu ...)
- imagemagick 8:7.1.2.26+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6jwg-7q3p-5fqm
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/3fc646a498eecda9163164046189f90dc677ae64
(7.1.2-26)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/eed471c1286aa27c076348b453b35a2e962967bc
(6.9.13-51)
CVE-2026-61859 (ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51
contains a p ...)
- imagemagick 8:7.1.2.26+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vghg-5jrg-2398
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/e047ee2c7b937c1db92302fe3701e2e9c169de27
(7.1.2-26)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/ffc96e2a4cdc2fcbb9e0f18f082be52e1b4ca012
(6.9.13-51)
@@ -1260,6 +1272,7 @@ CVE-2026-61605
REJECTED
CVE-2026-61464 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a
heap-based buffer ...)
- imagemagick 8:7.1.2.26+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-76q6-2p6h-xjqr
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/378bfc12bf7bbc4d9ab081120873efef935ebd85
(7.1.2-26)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/d0aa5c9e09e0cf5e400309ca76ae886a980b0555
(6.9.13-51)
@@ -1383,6 +1396,7 @@ CVE-2026-56398 (Open WebUI before 0.9.5 contains a stored
cross-site scripting v
NOT-FOR-US: Open WebUI
CVE-2026-56375 (ImageMagick through 7.1.2-18 contains a memory leak
vulnerability in t ...)
- imagemagick 8:7.1.2.18+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6p22-q7w5-33pg
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/3f55da39c813cc44ff21a61d6e0b85c375a2c1a2
(7.1.2-18)
CVE-2026-56353 (n8n contains an authentication bypass in the Chat Trigger node
when co ...)
@@ -4510,26 +4524,31 @@ CVE-2026-15470 (A vulnerability has been found in
Eleveo Call Recording Software
NOT-FOR-US: Eleveo Call Recording Software
CVE-2026-61870 (ImageMagick before 7.1.2-26 contains a memory leak
vulnerability in th ...)
- imagemagick 8:7.1.2.26+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m596-67p7-69wh
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/fdbf39ba9a681e53e6025d40501ae5a2bfec3000
(7.1.2-26)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/3c574f9ba5387f5f11669fdb4d4e8febc199dca3
(6.9.13-51)
CVE-2026-61861 (ImageMagick before 7.1.2-26 contains a use-after-free
vulnerability in ...)
- imagemagick 8:7.1.2.26+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qvxh-prvr-85w2
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/f89d59c5370cc48b758148cbdbea84c50511fee8
(7.1.2-26)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/0091f38a106601893c77c2d298708048cd2930f5
(6.9.13-51)
CVE-2026-61858 (ImageMagick before 7.1.2-26 contains a policy bypass
vulnerability in ...)
- imagemagick 8:7.1.2.26+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v3j6-27vc-7pw2
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/19c11cb0aefbd627c95c4c08c44722e660025aa1
(7.1.2-26)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/5fbcfe76fd8be554e30ec1d8723c00ae8b68f470
(6.9.13-51)
CVE-2026-61857 (ImageMagick before 7.1.2-26 contains a heap use-after-free
vulnerabili ...)
- imagemagick 8:7.1.2.26+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qh5g-q395-cx4j
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/150c9852402ac1aa1f223e5bf5109e3a2022ebbc
(7.1.2-26)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/e1d94d92d985f8c0bb648ddbcd70ba3362a84674
(6.9.13-51)
CVE-2026-61465 (ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check
for the a ...)
- imagemagick 8:7.1.2.26+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-rvhp-75f6-9jqh
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/dd0dedbecff931e93c4e72a57f7108bb13f76cf7
(7.1.2-26)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/0bcf10763277cdf0f61cf85e786575ae8665f13b
(7.1.2-26)
@@ -4565,6 +4584,7 @@ CVE-2026-56763 (Hono before 4.12.7 allows __proto__ key
in parseBody with dot op
NOT-FOR-US: Hono
CVE-2026-56372 (ImageMagick before 7.1.2-19 contains a heap buffer overflow
vulnerabil ...)
- imagemagick 8:7.1.2.19+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8vfj-q2cp-5m5j
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/8f6b59383ce65d839ad3e2aa578d5d7a7dd1d0ec
(7.1.2-19)
CVE-2026-56303 (Capgo before 12.128.2 contains an information disclosure
vulnerability ...)
@@ -5063,12 +5083,14 @@ CVE-2026-56664 (ZITADEL is an open source identity
management platform. Prior to
CVE-2026-56373 (ImageMagick before 7.1.2-15 contains a use-after-free
vulnerability in ...)
{DLA-4680-1}
- imagemagick 8:7.1.2.15+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3j4x-rwrx-xxj9
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/168ffe18def968f886c023146a478897866fd621
(7.1.2-14)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/06a0867c1f5076b85577b6b1cf87af901f6d6a84
(6.9.13-39)
CVE-2026-56366 (ImageMagick before 7.1.2-18 contains a memory leak
vulnerability in th ...)
{DLA-4680-1}
- imagemagick 8:7.1.2.18+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9r56-3gjq-hqf7
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/bee248ee853a686a969fae9cfb1e02dd5aae245b
(7.1.2-18)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick6/commit/1adc49fac3041620abe11fcb06524d33d9dbd035
(6.9.13-43)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/24f97375835402e2468ea7a46c4ba6b04dd4c653
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/24f97375835402e2468ea7a46c4ba6b04dd4c653
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits