[Buildroot] [PATCH 1/1] package/imagemagick: security bump to version 7.10.51

Peter Korsgaard peter at korsgaard.com
Tue Dec 22 10:54:40 UTC 2020


>>>>> "Fabrice" == Fabrice Fontaine <fontaine.fabrice at gmail.com> writes:

 > - Fix CVE-2020-29599: ImageMagick before 6.9.11-40 and 7.x before
 >   7.0.10-40 mishandles the -authenticate option, which allows setting a
 >   password for password-protected PDF files. The user-controlled password
 >   was not properly escaped/sanitized and it was therefore possible to
 >   inject additional shell commands via coders/pdf.c.
 > - Update license hash (correct wording to match Apache 2 license:
 >   https://github.com/ImageMagick/ImageMagick/commit/45e5d2493c08e7cb49f7268c01d847e88f78fd6c)

 > https://github.com/ImageMagick/ImageMagick/blob/7.0.10-51/ChangeLog

 > Signed-off-by: Fabrice Fontaine <fontaine.fabrice at gmail.com>

Committed to 2020.02.x, 2020.08.x and 2020.11.x, thanks.

-- 
Bye, Peter Korsgaard



More information about the buildroot mailing list