Security News

Cybersecurity news aggregator

🐧
HIGH Updates Debian Security

DSA-6169-1 imagemagick - security update

Multiple vulnerabilities (CVE-2026-28493, CVE-2026-28494, CVE-2026-28686, etc.) in ImageMagick could lead to symlink races, information leaks, denial of service, or arbitrary code execution. The CVSS scores range from Medium to High, with CVE-2026-28494 rated at 7.1 (High). Affected versions include ImageMagick before 6.9.13-41 and versions 7.0.0-0 through 7.1.2-15; the fixed versions are 6.9.13-41 and 7.1.2-16.
Read Full Article →

[SECURITY] [DSA 6169-1] imagemagick security update To : debian-security-announce@lists.debian.org Subject : [SECURITY] [DSA 6169-1] imagemagick security update From : Moritz Muehlenhoff < jmm@debian.org > Date : Thu, 19 Mar 2026 21:46:45 +0000 Message-id : < [🔎] abxuxZsfsbtGfHxv@seger.debian.org > Reply-to : debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6169-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff March 19, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : imagemagick CVE ID : CVE-2026-28493 CVE-2026-28494 CVE-2026-28686 CVE-2026-28687 CVE-2026-28688 CVE-2026-28689 CVE-2026-28690 CVE-2026-28691 CVE-2026-28692 CVE-2026-28693 CVE-2026-30883 CVE-2026-30929 CVE-2026-30931 CVE-2026-30935 CVE-2026-30936 CVE-2026-30937 CVE-2026-31853 CVE-2026-32259 Multiple security vulnerabilities were discovered in imagemagick, a software suite used for editing and manipulating digital images, which could lead to symlink races, information leaks, denial of service and potentially arbitrary code execution. For the stable distribution (trixie), these problems have been fixed in version 8:7.1.1.43+dfsg1-1+deb13u7. We recommend that you upgrade your imagemagick packages. For the detailed security status of imagemagick please refer to its security tracker page at: https://security-tracker.debian.org/tracker/imagemagick Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmm8bnYACgkQEMKTtsN8 TjZc+xAAmyjYFijF0LTQbirsjj0wbNZtEk0JYxfPae6YfnhG96L8QF6URRUfkKP/ iVR6+RIkjIX/4YARGLmXTlP8FQWceFHJ37nDnxbTREymifsmrUfI5/Ohi86Cl2N1 GdNrCRfnA5W3mKfDdp7bOd34o9M0V6b9pOjjGKu4c+dj3QvhusZs4CBQVrLrx6kN A7dVRiFeodRmjQQ+PQC6vo9giw3CM3KKfFfTPoHk763YIzLCVjpP66AzPUlb/cFc kpLNzdVy9QJPz2e/nYJpQrv/WVlnJn4QTrhYUDlfCcM6U22CzMIpo3ZA99GMMWTw RHocN3YAqWeB6rN1+V9ORRUg26Qspxxxnlo4XvXkM8uVAx24Jki2AwyOylChOb4s Ibg5i/rRUwM7/4PS/EvoBH6i0Uj5VoFR5xN2LWYu29GLiNKDZkuU7PPyVmC0wvRt 6Ci3Huw0asg3wPtPBRMzkupzjm/MdkrZaNik4DuAIJvMkyhkggBn6uzuHcdsLN/e EX6IRgbOPLXnP8s8LoW4VQhXzortXfZ0tyVilMLjeOJxlXdn3JzbQjb6+/cnVqJ9 GndoBXZPeY3xlLiTb9mdaXLFjH0EIfdfOaFJWH/QLI6cqeoolDuSK/yvAZ0fE3Qa so6LOqgyt5KdO1MFHcZf/245E4p+Dxb4d1SewMmtPFHtmkJMOAY= =2RFB -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Moritz Muehlenhoff (on-list) Moritz Muehlenhoff (off-list) Prev by Date: [SECURITY] [DSA 6168-1] freetype security update Next by Date: [SECURITY] [DSA 6170-1] snapd security update Previous by thread: [SECURITY] [DSA 6168-1] freetype security update Next by thread: [SECURITY] [DSA 6170-1] snapd security update Index(es): Date Thread

Share this article