-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 11 Apr 2025 22:49:23 +0200 Source: graphicsmagick Binary: graphicsmagick graphicsmagick-dbg libgraphics-magick-perl libgraphicsmagick++-q16-12 libgraphicsmagick++1-dev libgraphicsmagick-q16-3 libgraphicsmagick1-dev Architecture: armel Version: 1.4+really1.3.40-4+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-conova-02) Changed-By: Salvatore Bonaccorso Description: graphicsmagick - collection of image processing tools graphicsmagick-dbg - format-independent image processing - debugging symbols libgraphics-magick-perl - format-independent image processing - perl interface libgraphicsmagick++-q16-12 - format-independent image processing - C++ shared library libgraphicsmagick++1-dev - format-independent image processing - C++ development files libgraphicsmagick-q16-3 - format-independent image processing - C shared library libgraphicsmagick1-dev - format-independent image processing - C development files Closes: 1099955 Changes: graphicsmagick (1.4+really1.3.40-4+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. . [ Carlos Henrique Lima Melara ] * d/p/CVE-2025-27795.patch: fix CVE-2025-27795 by adding image dimension resource limits. (Closes: #1099955) . [ Salvatore Bonaccorso ] * ReadJXLImage(): pixel_format.num_channels needs to be 2 for grayscale matte (CVE-2025-32460) Checksums-Sha1: cbe09fb7df3b18c2fcb6bbcbcc5669fa247ac561 4138844 graphicsmagick-dbg_1.4+really1.3.40-4+deb12u1_armel.deb 183aa321ce1ff14187b6c0d4f82e69d8aca2d01f 11137 graphicsmagick_1.4+really1.3.40-4+deb12u1_armel-buildd.buildinfo db35c0ecdd824db28afcac0b3c3ba62b5c208298 1019632 graphicsmagick_1.4+really1.3.40-4+deb12u1_armel.deb d422c7626430be49b1ed7c42f0c3451960bd31eb 59480 libgraphics-magick-perl_1.4+really1.3.40-4+deb12u1_armel.deb 77b7a4468a98e20351b23237ed14214897eaa201 97804 libgraphicsmagick++-q16-12_1.4+really1.3.40-4+deb12u1_armel.deb 6a5a2e68c1f551e56f711c8877fbb24eb0c767bf 288784 libgraphicsmagick++1-dev_1.4+really1.3.40-4+deb12u1_armel.deb ec6102d0a85cd54688b658010bece6e9324e8eb8 1097652 libgraphicsmagick-q16-3_1.4+really1.3.40-4+deb12u1_armel.deb 28d06aa9a92bf56fc3de38222d4352a726ff04a3 1366800 libgraphicsmagick1-dev_1.4+really1.3.40-4+deb12u1_armel.deb Checksums-Sha256: 7f584edff8e1ead9907524f0b7ba94b5c260fe82fdbb788178878f67a9860b40 4138844 graphicsmagick-dbg_1.4+really1.3.40-4+deb12u1_armel.deb 382ab3dfb40799930d5958b145450f281db14b708854eced5584d11eb52f70ac 11137 graphicsmagick_1.4+really1.3.40-4+deb12u1_armel-buildd.buildinfo 129233218df7fcb8bcdeccbfa5151dcd0c00f45194bbf1bbc079b94144160ed4 1019632 graphicsmagick_1.4+really1.3.40-4+deb12u1_armel.deb f59e6c0fc99aa2594f20fc091ebb98efbb6d6044ce726338d7141cca39d4c528 59480 libgraphics-magick-perl_1.4+really1.3.40-4+deb12u1_armel.deb 1b3ff90ec8212a083818720acec9a533cdb87e84a16f279c81cba82785235bb3 97804 libgraphicsmagick++-q16-12_1.4+really1.3.40-4+deb12u1_armel.deb db32060def52fca348b66b5c79369e3f86fadbe61b3b1d5f3b893c287a3d9a28 288784 libgraphicsmagick++1-dev_1.4+really1.3.40-4+deb12u1_armel.deb 44fbf209206ce92dc6d7d82549afe27e23bab9975e9de97b021a8093a9564eb7 1097652 libgraphicsmagick-q16-3_1.4+really1.3.40-4+deb12u1_armel.deb 3b503ee5b2e549a583995e4445f3b715114e40391b8ebe5ac34149dee92a1a8f 1366800 libgraphicsmagick1-dev_1.4+really1.3.40-4+deb12u1_armel.deb Files: 3d8c6993f523f18698bcc983ddd32510 4138844 debug optional graphicsmagick-dbg_1.4+really1.3.40-4+deb12u1_armel.deb 7771fe5db6f234f7737eada2f487c148 11137 graphics optional graphicsmagick_1.4+really1.3.40-4+deb12u1_armel-buildd.buildinfo eb65f9c3fc4e1c7af575ca2230070426 1019632 graphics optional graphicsmagick_1.4+really1.3.40-4+deb12u1_armel.deb b921c37fd3f2a567986d332cf9421741 59480 perl optional libgraphics-magick-perl_1.4+really1.3.40-4+deb12u1_armel.deb 22fce2dcfe3af2bf95f81a4706698f6b 97804 libs optional libgraphicsmagick++-q16-12_1.4+really1.3.40-4+deb12u1_armel.deb 2ab00b67bdc8d1690e29d50d616cf625 288784 libdevel optional libgraphicsmagick++1-dev_1.4+really1.3.40-4+deb12u1_armel.deb f5a46c56f4a2df08c14330339d27593c 1097652 libs optional libgraphicsmagick-q16-3_1.4+really1.3.40-4+deb12u1_armel.deb a78d15721ca2296e02ccb339b7c2d757 1366800 libdevel optional libgraphicsmagick1-dev_1.4+really1.3.40-4+deb12u1_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKAzExpjGvTI78ZO8LARVyvnD3xkFAmf5id0ACgkQLARVyvnD 3xlgFA//dcx6zWe1xg97t6LLQIUJIQw9/ABEJltF9nHqTpMCMMGIhYtrBT6flVns 4FtDQlKzG0uzRzl0A1/hDgqQjYkqjBTOlCthqzIbQahHrnrHC4z/3bwPYDEomXvZ 9zWqBIaQAvh+ECFp8LoN+hhDqny7vfBnRZ4XWlbRxAOJ7OQpX6vkV04v0WuMVvRy mRj3YXCN5dz2MaY2v/LFJPi8n3WmRmMmNwl+cZF2klyZ2lovZiyTaNbrGeMbI+Bo 1kXJg1Vj7bAZaOuc0nSuf6xfEOHkiXCXn/73DLIsedF3oFKnByi82fXdzSdRQXrc QKmZSqP5OzkftiPMNX+3T5w8ISX7p6N54gnLE829X6nKr8R7LlpZutFwtcIS8iVN e/PP+64rD+53QjXD3DNz7f1pFThJQS9TrnxNqZUcsCgci3u6Epm4jBkswrOsBegG 5IBSZZFLEm4sbnwLZm4KPeRGY48cvo6JFkIOEHesVO5H08ZyGu6+9C322WroxQbw Hii0e3JMJ+vPcKmPUndiP6RT+Yj7IkndYJ8KC0WMuCCqjHqu1S73bbCjq5DUT11w n1DZpoiTcecLpH7oY06G4Keb+xeSw+TsTG+B2ug0VXOG1d1Rl9Emb6eUuTGzcMDE MCWkgfrrM7FphPwkJK7kCuqTbnfM7YO4nYqCUQ0lsgsIehzsLM4= =0Cny -----END PGP SIGNATURE-----