UbuntuUpdates.org

Package "graphicsmagick-dbg"

Name: graphicsmagick-dbg

Description:

format-independent image processing - debugging symbols

Latest version: 1.4+really1.3.45-1ubuntu0.1
Release: oracular (24.10)
Level: updates
Repository: universe
Head package: graphicsmagick
Homepage: http://www.graphicsmagick.org/

Links


Download "graphicsmagick-dbg"


Other versions of "graphicsmagick-dbg" in Oracular

Repository Area Version
base universe 1.4+really1.3.45-1
security universe 1.4+really1.3.45-1ubuntu0.1

Changelog

Version: 1.4+really1.3.45-1ubuntu0.1 2025-04-14 03:06:52 UTC

  graphicsmagick (1.4+really1.3.45-1ubuntu0.1) oracular-security; urgency=medium

  * SECURITY UPDATE: Excessive Memory Consumption
    - debian/patches/CVE-2025-27795.patch: Add check for image dimensions
    - CVE-2025-27795
  * SECURITY UPDATE: Out-of-bounds Access
    - debian/patches/CVE-2025-27796.patch: Ensure buffer is properly
      allocated
    - CVE-2025-27796

 -- Bruce Cable <email address hidden> Fri, 11 Apr 2025 18:37:03 +1000

CVE-2025-27795 ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.
CVE-2025-27796 ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlo



About   -   Send Feedback to @ubuntu_updates