-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 11 Apr 2025 22:49:23 +0200 Source: graphicsmagick Binary: graphicsmagick graphicsmagick-dbg libgraphics-magick-perl libgraphicsmagick++-q16-12 libgraphicsmagick++1-dev libgraphicsmagick-q16-3 libgraphicsmagick1-dev Architecture: armhf Version: 1.4+really1.3.40-4+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-conova-03) Changed-By: Salvatore Bonaccorso Description: graphicsmagick - collection of image processing tools graphicsmagick-dbg - format-independent image processing - debugging symbols libgraphics-magick-perl - format-independent image processing - perl interface libgraphicsmagick++-q16-12 - format-independent image processing - C++ shared library libgraphicsmagick++1-dev - format-independent image processing - C++ development files libgraphicsmagick-q16-3 - format-independent image processing - C shared library libgraphicsmagick1-dev - format-independent image processing - C development files Closes: 1099955 Changes: graphicsmagick (1.4+really1.3.40-4+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. . [ Carlos Henrique Lima Melara ] * d/p/CVE-2025-27795.patch: fix CVE-2025-27795 by adding image dimension resource limits. (Closes: #1099955) . [ Salvatore Bonaccorso ] * ReadJXLImage(): pixel_format.num_channels needs to be 2 for grayscale matte (CVE-2025-32460) Checksums-Sha1: 8fb7785f25fef10ee68ef3f2eb62ce4181492569 4139828 graphicsmagick-dbg_1.4+really1.3.40-4+deb12u1_armhf.deb 9a76c37d4dc41431f06a546576ba6290e1df5351 11139 graphicsmagick_1.4+really1.3.40-4+deb12u1_armhf-buildd.buildinfo 7fcdf4403f3a219fe231e0857308f7cfbc16154c 1019652 graphicsmagick_1.4+really1.3.40-4+deb12u1_armhf.deb 9a33eabb492d6a112e16066cfb3ae06c1cf9588d 59440 libgraphics-magick-perl_1.4+really1.3.40-4+deb12u1_armhf.deb 76debbe323c8b679921fa3060ea37414c9fe67bc 98448 libgraphicsmagick++-q16-12_1.4+really1.3.40-4+deb12u1_armhf.deb ac5a1124addb9a4496a2b9d762c6c42590942d49 286868 libgraphicsmagick++1-dev_1.4+really1.3.40-4+deb12u1_armhf.deb c59753cc5159320bd4e8514867414431cbcd35d8 1077244 libgraphicsmagick-q16-3_1.4+really1.3.40-4+deb12u1_armhf.deb 4525ba6735a5fe4f0be99bb8f45bb5c9139b7976 1340692 libgraphicsmagick1-dev_1.4+really1.3.40-4+deb12u1_armhf.deb Checksums-Sha256: f30249bb39eff0eab20cfc2d4144f1e63afa9a02f7548f62079adf07e4675d89 4139828 graphicsmagick-dbg_1.4+really1.3.40-4+deb12u1_armhf.deb 003d87c3fe9e1333ea966405939624a23940befe8eb1a9e6ce3890ee6d2b82e2 11139 graphicsmagick_1.4+really1.3.40-4+deb12u1_armhf-buildd.buildinfo 758e5ca1e10b49051d71a1d1af44beb8b91d41d2def6c44f0dae15a992c4de74 1019652 graphicsmagick_1.4+really1.3.40-4+deb12u1_armhf.deb 0f97f8906f4a719fb3f03adcc96e782f5140f2a9c3875a36c110ffcd4d399a9a 59440 libgraphics-magick-perl_1.4+really1.3.40-4+deb12u1_armhf.deb 1e0fdde8344b1134f441caf63e4cc79b52837bbb59fa423fc8745d66fd6ed257 98448 libgraphicsmagick++-q16-12_1.4+really1.3.40-4+deb12u1_armhf.deb b20828ff266a355e6f06657b124b152572bb7145fc74de471764a90b06d168b5 286868 libgraphicsmagick++1-dev_1.4+really1.3.40-4+deb12u1_armhf.deb d712f0c2e2d5cef396d50d59b4f460f2d9744953cca9376e1ca3a8b818b317f9 1077244 libgraphicsmagick-q16-3_1.4+really1.3.40-4+deb12u1_armhf.deb 59564c13ef3bc6ecc8fd46853159901e0eb4b5f432d747a492d766ef6f50f46d 1340692 libgraphicsmagick1-dev_1.4+really1.3.40-4+deb12u1_armhf.deb Files: 09a468b0dc99770e893235466fbd95eb 4139828 debug optional graphicsmagick-dbg_1.4+really1.3.40-4+deb12u1_armhf.deb b51f4f6972ab2b7da3f0a8bd5adf79cd 11139 graphics optional graphicsmagick_1.4+really1.3.40-4+deb12u1_armhf-buildd.buildinfo 53fc33769f312610d9615d4a35711538 1019652 graphics optional graphicsmagick_1.4+really1.3.40-4+deb12u1_armhf.deb 9299d237ee5c3bf1f4d17497661e24a1 59440 perl optional libgraphics-magick-perl_1.4+really1.3.40-4+deb12u1_armhf.deb 16b0adcadf6d44cad0d69987d9bc6f01 98448 libs optional libgraphicsmagick++-q16-12_1.4+really1.3.40-4+deb12u1_armhf.deb 42c4ff14ec9985627ed121cc96175189 286868 libdevel optional libgraphicsmagick++1-dev_1.4+really1.3.40-4+deb12u1_armhf.deb f0bb0bd2b311fb93d7208e3633217c49 1077244 libs optional libgraphicsmagick-q16-3_1.4+really1.3.40-4+deb12u1_armhf.deb 6cc15fd2117b679ca3621d5a0561c621 1340692 libdevel optional libgraphicsmagick1-dev_1.4+really1.3.40-4+deb12u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEVM4SKBZumztS8zr3lST9Us03ywsFAmf5iVIACgkQlST9Us03 ywuF4BAAhNcZxndiy21QhdAVzpYkCnfNci582YkYvIKPCOzisK0JJHJf+ATEkcqI AMhsUOaW8xkpTac2KOJHqmE0PCurp7tHydca0TpgL7wWtDr5eAi9cB+xWMCWBf+q xOyaNeNeylnFDVrHCpN9OGgYOBXhpgtHA3STqvEfknzDo5y1Woj2LoWAgZBVRcWY ZX9Jjmgdise0qkxRfckTVkZxL+6ZjgygO5llqRap8YWHUaLu6okmRX2LD4FEjt+3 BcplCH0okDx6qNLN3+DX8y1V3e8hItbR3+Gea+iKBJKjFW894Dem45AsZMzp5BkU 2sSMkDqlgTypMhHUFFz3vqzwApuXCmm33rNfI2cUhN6ONZPtDxyFNGDHodDDO5JK PWEQRbXq0YPMOgcjTnPQa18U+ZfjkwrXQQu/JXSxgW+IYwsPAwDNwSeSK94WolLv BOf1FXrq38LnfNcAER3yma5mKe/HzIBvy6UynI0jiGa3/4tJGO8SXg/ewk9a4gI1 oB9EC2rqNmCPNDn8rp9o83PFihvSsy9qXBKdLkqeEdQFt6/cV11SxMpmVB8V7DuK 9m67vk1zt4u2sCfuuxsNAY+3J8LZ3cGdStapDl7xOw7YWlmiEVT4Xq60UwAXYPio J3hwTE22Q1RAsrn0UZMXQWw/4qUzKmEap8yK/5cgikOq63IdrMM= =NJd6 -----END PGP SIGNATURE-----