Bug 28088 - graphicsmagick 1.3.36 fixes security issues
Summary: graphicsmagick 1.3.36 fixes security issues
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2021-01-13 20:07 CET by David Walser
Modified: 2021-06-25 16:45 CEST (History)
4 users (show)

See Also:
Source RPM: graphicsmagick-1.3.35-3.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2021-01-13 20:07:23 CET
GraphicsMagick 1.3.36 has been released on December 26:
http://www.graphicsmagick.org/NEWS.html#december-26-2020

Fedora has issued an advisory for this on January 6:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/EWADQNGPBUDR6HVZJFSUI4BIPMAK75EN/

Mageia 7 is also affected.
David Walser 2021-01-13 20:24:39 CET

Whiteboard: (none) => MGA7TOO

Comment 1 Nicolas Lécureuil 2021-01-13 21:28:42 CET
push freeze asked for cauldron.

Whiteboard: MGA7TOO => (none)
CC: (none) => mageia
Version: Cauldron => 7

Comment 2 Lewis Smith 2021-01-14 14:27:56 CET
Assigning to Stig as having done previous M7 updates for this thing.

Assignee: bugsquad => smelror

Comment 3 David Walser 2021-06-22 00:39:42 CEST
Advisory:
========================

Updated graphicsmagick packages fix security vulnerabilities:

The graphicsmagick package has been updated to version 1.3.36, fixing several
security issues and other bugs.  See the upstream NEWS file for details.

References:
http://www.graphicsmagick.org/NEWS.html#december-26-2020
========================

Updated packages in core/updates_testing:
========================
graphicsmagick-1.3.36-1.mga7
libgraphicsmagick3-1.3.36-1.mga7
libgraphicsmagick++12-1.3.36-1.mga7
libgraphicsmagickwand2-1.3.36-1.mga7
libgraphicsmagick-devel-1.3.36-1.mga7
perl-Graphics-Magick-1.3.36-1.mga7
graphicsmagick-doc-1.3.36-1.mga7

from graphicsmagick-1.3.36-1.mga7.src.rpm

Assignee: smelror => qa-bugs

Comment 4 Herman Viaene 2021-06-23 15:25:13 CEST
MGA7-64 Plasma on Lenovo B50
No installation issues.
Followed wiki https://wiki.mageia.org/en/QA_procedure:GraphicsMagick
Only remark:
$ gm convert IMG_1272.jpg IMG_1272.tiff
gm convert: IMG_1272.tiff: Invalid tag "Predictor" (not supported by codec). (_TIFFVGetField).
But the tiff file is generated OK, so all OK for me.

Whiteboard: (none) => MGA7-64-OK
CC: (none) => herman.viaene

Comment 5 Thomas Andrews 2021-06-24 02:08:51 CEST
Validating. Advisory in Comment 3.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Thomas Backlund 2021-06-25 15:30:29 CEST

Keywords: (none) => advisory

Comment 6 Mageia Robot 2021-06-25 16:45:16 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0286.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.