Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
24f97375 by Salvatore Bonaccorso at 2026-07-17T21:26:55+02:00
Triage imagemagick for trixie

All of the currently open issues in trixie seem fairly low severity so
they IMHO can be included in a future update or a point release.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1173,56 +1173,68 @@ CVE-2026-61873 (Grav before 9.1.8 contains an arbitrary 
file write vulnerability
        NOT-FOR-US: Grav CMS
 CVE-2026-61872 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory 
leak in th ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h5r4-w88w-7ccr
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/ed143b98d72bba764b010eb822464f2a12b24ff1
 (7.1.2-26)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/3f0595f0778201326163253bfdc8bce9a4bbadf6
 (6.9.13-51)
 CVE-2026-61871 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory 
leak in th ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h58x-r7f7-rh84
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/b237a4fa9cbffcb11ee579d386fd37c570d5dffe
 (7.1.2-26)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/e4b68bfb6a9541a9c3a4af81a21bf0c253661083
 (6.9.13-51)
 CVE-2026-61869 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory 
leak in th ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r628-69v2-2f9c
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/b2dc602e175ee07b0794f3e31f1a29ae6b7267d1
 (7.1.2-26)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/ca6c9da425880fde937da41d59666dedf5e719e1
 (6.9.13-51)
 CVE-2026-61868 (ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 
contains a memo ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h7f2-f9cc-h2gv
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/808506dc4d0cbf3972ce0d57544a06209b65009c
 (7.1.2-26)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/875bd8912b3b54a58e09c14085cf2b14a478a86b
 (6.9.13-51)
 CVE-2026-61867 (ImageMagick before 7.1.2-26 contains a memory leak 
vulnerability in th ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-jfq9-q63x-rc63
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/f34065ecd9512df16cb10083c8b4b46b5cd09b30
 (7.1.2-26)
 CVE-2026-61866 (ImageMagick before 7.1.2-26 contains a memory leak 
vulnerability in th ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-99w9-hv66-rfv7
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/0bb3578ee087f3c4f14bbf1d8883ae456fc99092
 (7.1.2-26)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/353e2604d1983b6d8ec4c04f4f38bbd4668ba0e1
 (6.9.13-51)
 CVE-2026-61865 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory 
leak in th ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-j8rh-v2r8-v94x
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/b535126ba5abf23f2693e62ed79f10277d938cf4
 (7.1.2-26)
 CVE-2026-61864 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory 
leak in co ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7c7m-fpjw-gwcq
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/174275bc1b53e2f23bbff7cd013dc9faa8a99c5a
 (7.1.2-26)
 CVE-2026-61863 (ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) 
contains a memo ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6vxp-gfwf-hcr9
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/f3ff3afee942a19e3041568bfa740d48213a3dec
 (7.1.2-26)
 CVE-2026-61862 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains an 
information disc ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hwf3-r46v-5ggx
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/4079949bae0cde7e683df2e63c40f2e36f52c1b6
 (7.1.2-26)
 CVE-2026-61860 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a 
use-after-free vu ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6jwg-7q3p-5fqm
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/3fc646a498eecda9163164046189f90dc677ae64
 (7.1.2-26)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/eed471c1286aa27c076348b453b35a2e962967bc
 (6.9.13-51)
 CVE-2026-61859 (ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 
contains a p ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vghg-5jrg-2398
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/e047ee2c7b937c1db92302fe3701e2e9c169de27
 (7.1.2-26)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/ffc96e2a4cdc2fcbb9e0f18f082be52e1b4ca012
 (6.9.13-51)
@@ -1260,6 +1272,7 @@ CVE-2026-61605
        REJECTED
 CVE-2026-61464 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a 
heap-based buffer ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-76q6-2p6h-xjqr
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/378bfc12bf7bbc4d9ab081120873efef935ebd85
 (7.1.2-26)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/d0aa5c9e09e0cf5e400309ca76ae886a980b0555
 (6.9.13-51)
@@ -1383,6 +1396,7 @@ CVE-2026-56398 (Open WebUI before 0.9.5 contains a stored 
cross-site scripting v
        NOT-FOR-US: Open WebUI
 CVE-2026-56375 (ImageMagick through 7.1.2-18 contains a memory leak 
vulnerability in t ...)
        - imagemagick 8:7.1.2.18+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6p22-q7w5-33pg
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/3f55da39c813cc44ff21a61d6e0b85c375a2c1a2
 (7.1.2-18)
 CVE-2026-56353 (n8n contains an authentication bypass in the Chat Trigger node 
when co ...)
@@ -4510,26 +4524,31 @@ CVE-2026-15470 (A vulnerability has been found in 
Eleveo Call Recording Software
        NOT-FOR-US: Eleveo Call Recording Software
 CVE-2026-61870 (ImageMagick before 7.1.2-26 contains a memory leak 
vulnerability in th ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m596-67p7-69wh
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/fdbf39ba9a681e53e6025d40501ae5a2bfec3000
 (7.1.2-26)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/3c574f9ba5387f5f11669fdb4d4e8febc199dca3
 (6.9.13-51)
 CVE-2026-61861 (ImageMagick before 7.1.2-26 contains a use-after-free 
vulnerability in ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qvxh-prvr-85w2
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/f89d59c5370cc48b758148cbdbea84c50511fee8
 (7.1.2-26)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/0091f38a106601893c77c2d298708048cd2930f5
 (6.9.13-51)
 CVE-2026-61858 (ImageMagick before 7.1.2-26 contains a policy bypass 
vulnerability in  ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v3j6-27vc-7pw2
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/19c11cb0aefbd627c95c4c08c44722e660025aa1
 (7.1.2-26)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/5fbcfe76fd8be554e30ec1d8723c00ae8b68f470
 (6.9.13-51)
 CVE-2026-61857 (ImageMagick before 7.1.2-26 contains a heap use-after-free 
vulnerabili ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qh5g-q395-cx4j
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/150c9852402ac1aa1f223e5bf5109e3a2022ebbc
 (7.1.2-26)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/e1d94d92d985f8c0bb648ddbcd70ba3362a84674
 (6.9.13-51)
 CVE-2026-61465 (ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check 
for the a ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-rvhp-75f6-9jqh
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/dd0dedbecff931e93c4e72a57f7108bb13f76cf7
 (7.1.2-26)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/0bcf10763277cdf0f61cf85e786575ae8665f13b
 (7.1.2-26)
@@ -4565,6 +4584,7 @@ CVE-2026-56763 (Hono before 4.12.7 allows __proto__ key 
in parseBody with dot op
        NOT-FOR-US: Hono
 CVE-2026-56372 (ImageMagick before 7.1.2-19 contains a heap buffer overflow 
vulnerabil ...)
        - imagemagick 8:7.1.2.19+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8vfj-q2cp-5m5j
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/8f6b59383ce65d839ad3e2aa578d5d7a7dd1d0ec
 (7.1.2-19)
 CVE-2026-56303 (Capgo before 12.128.2 contains an information disclosure 
vulnerability ...)
@@ -5063,12 +5083,14 @@ CVE-2026-56664 (ZITADEL is an open source identity 
management platform. Prior to
 CVE-2026-56373 (ImageMagick before 7.1.2-15 contains a use-after-free 
vulnerability in ...)
        {DLA-4680-1}
        - imagemagick 8:7.1.2.15+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3j4x-rwrx-xxj9
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/168ffe18def968f886c023146a478897866fd621
 (7.1.2-14)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/06a0867c1f5076b85577b6b1cf87af901f6d6a84
 (6.9.13-39)
 CVE-2026-56366 (ImageMagick before 7.1.2-18 contains a memory leak 
vulnerability in th ...)
        {DLA-4680-1}
        - imagemagick 8:7.1.2.18+dfsg1-1
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9r56-3gjq-hqf7
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/bee248ee853a686a969fae9cfb1e02dd5aae245b
 (7.1.2-18)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/1adc49fac3041620abe11fcb06524d33d9dbd035
 (6.9.13-43)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/24f97375835402e2468ea7a46c4ba6b04dd4c653

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/24f97375835402e2468ea7a46c4ba6b04dd4c653
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to