diff -Nru imagemagick-6.7.7.10/debian/changelog imagemagick-6.7.7.10/debian/changelog --- imagemagick-6.7.7.10/debian/changelog 2018-06-08 16:42:48.000000000 +0000 +++ imagemagick-6.7.7.10/debian/changelog 2018-06-11 13:26:35.000000000 +0000 @@ -1,4 +1,4 @@ -imagemagick (8:6.7.7.10-6ubuntu3.10) trusty-security; urgency=medium +imagemagick (8:6.7.7.10-6ubuntu3.11) trusty-security; urgency=medium * SECURITY UPDATE: Multiple security issues - debian/patches/*: synchronize security fixes with Debian's @@ -13,18 +13,18 @@ CVE-2017-12563, CVE-2017-12587, CVE-2017-12640, CVE-2017-12643, CVE-2017-12670, CVE-2017-12674, CVE-2017-12691, CVE-2017-12692, CVE-2017-12693, CVE-2017-12875, CVE-2017-12877, CVE-2017-12983, - CVE-2017-13133, CVE-2017-13134, CVE-2017-13139, CVE-2017-13142, - CVE-2017-13143, CVE-2017-13144, CVE-2017-13758, CVE-2017-13768, - CVE-2017-13769, CVE-2017-14060, CVE-2017-14172, CVE-2017-14173, - CVE-2017-14174, CVE-2017-14175, CVE-2017-14224, CVE-2017-14249, - CVE-2017-14325, CVE-2017-14341, CVE-2017-14342, CVE-2017-14343, - CVE-2017-14400, CVE-2017-14505, CVE-2017-14531, CVE-2017-14607, - CVE-2017-14682, CVE-2017-14739, CVE-2017-14741, CVE-2017-14989, - CVE-2017-15016, CVE-2017-15017, CVE-2017-15277, CVE-2017-15281, - CVE-2017-16546, CVE-2017-17504, CVE-2017-17682, CVE-2017-17879, - CVE-2017-17914, CVE-2017-18252, CVE-2017-18271, CVE-2017-18273, - CVE-2017-1000445, CVE-2017-1000476, CVE-2018-7443, CVE-2018-8804, - CVE-2018-8960,CVE-2018-10177, CVE-2018-11251 + CVE-2017-13134, CVE-2017-13139, CVE-2017-13142, CVE-2017-13143, + CVE-2017-13144, CVE-2017-13758, CVE-2017-13768, CVE-2017-13769, + CVE-2017-14060, CVE-2017-14172, CVE-2017-14173, CVE-2017-14174, + CVE-2017-14175, CVE-2017-14224, CVE-2017-14249, CVE-2017-14325, + CVE-2017-14341, CVE-2017-14342, CVE-2017-14343, CVE-2017-14400, + CVE-2017-14505, CVE-2017-14531, CVE-2017-14607, CVE-2017-14682, + CVE-2017-14739, CVE-2017-14741, CVE-2017-14989, CVE-2017-15016, + CVE-2017-15017, CVE-2017-15277, CVE-2017-15281, CVE-2017-16546, + CVE-2017-17504, CVE-2017-17682, CVE-2017-17879, CVE-2017-17914, + CVE-2017-18252, CVE-2017-18271, CVE-2017-18273, CVE-2017-1000445, + CVE-2017-1000476, CVE-2018-7443, CVE-2018-8804, CVE-2018-8960, + CVE-2018-10177, CVE-2018-11251 -- Marc Deslauriers Fri, 08 Jun 2018 12:00:47 -0400 diff -Nru imagemagick-6.7.7.10/debian/patches/0291-CVE-2017-13133-Fix-offset-validation-vulnerability-in-load_level-in-xcf.c.patch imagemagick-6.7.7.10/debian/patches/0291-CVE-2017-13133-Fix-offset-validation-vulnerability-in-load_level-in-xcf.c.patch --- imagemagick-6.7.7.10/debian/patches/0291-CVE-2017-13133-Fix-offset-validation-vulnerability-in-load_level-in-xcf.c.patch 2018-06-08 15:24:52.000000000 +0000 +++ imagemagick-6.7.7.10/debian/patches/0291-CVE-2017-13133-Fix-offset-validation-vulnerability-in-load_level-in-xcf.c.patch 1970-01-01 00:00:00.000000000 +0000 @@ -1,29 +0,0 @@ -From fad03699658d2607562a8487c944c300d59a1ca5 Mon Sep 17 00:00:00 2001 -From: Cristy -Date: Wed, 16 Aug 2017 15:13:07 -0400 -Subject: [PATCH] https://github.com/ImageMagick/ImageMagick/issues/679 - -bug: https://github.com/ImageMagick/ImageMagick/issues/679 -bug-debian: https://bugs.debian.org/873100 -origin: https://github.com/ImageMagick/ImageMagick/commit/fad03699658d2607562a8487c944c300d59a1ca5 - -(cherry picked from commit fad03699658d2607562a8487c944c300d59a1ca5) -[rcs: Backported to wheezy] ---- - coders/xcf.c | 3 +++ - 1 file changed, 3 insertions(+) - -Index: imagemagick-6.7.7.10/coders/xcf.c -=================================================================== ---- imagemagick-6.7.7.10.orig/coders/xcf.c 2018-06-08 11:24:50.929114993 -0400 -+++ imagemagick-6.7.7.10/coders/xcf.c 2018-06-08 11:24:50.929114993 -0400 -@@ -666,6 +666,9 @@ static MagickBooleanType load_level(Imag - allowing for negative compression */ - if (offset2 == 0) - offset2=(MagickOffsetType) (offset + TILE_WIDTH * TILE_WIDTH * 4* 1.5); -+ if (offset2 > GetBlobSize(image)) -+ ThrowBinaryException(CorruptImageError,"InsufficientImageDataInFile", -+ image->filename); - /* seek to the tile offset */ - offset=SeekBlob(image, offset, SEEK_SET); - diff -Nru imagemagick-6.7.7.10/debian/patches/series imagemagick-6.7.7.10/debian/patches/series --- imagemagick-6.7.7.10/debian/patches/series 2018-06-08 16:00:29.000000000 +0000 +++ imagemagick-6.7.7.10/debian/patches/series 2018-06-11 13:25:26.000000000 +0000 @@ -264,7 +264,6 @@ 0305-CVE-2017-12875-Fix-CPU-consumption-in-WritePixelCachePixels.patch 0289-CVE-2017-12877-Fix-use-after-free-in-ReadMATImage.patch 0290-CVE-2017-12983-Fix-heap-based-buffer-overflow-in-ReadSFWImage.patch -0291-CVE-2017-13133-Fix-offset-validation-vulnerability-in-load_level-in-xcf.c.patch 0292-CVE-2017-13134-Fix-heap-based-buffer-overflow-in-SFWScan.patch 0293-CVE-2017-13139-Fix-out-of-bounds-read-with-MNG-CLIP-chunk-in-ReadOneMNGImage.patch 0294-CVE-2017-13142-Fix-short-file-check-in-png.c-1-2.patch