#51301 closed update (fixed)
ImageMagick @6.9.3-4: Security update to 6.9.3-9
Reported by: | Schamschula (Marius Schamschula) | Owned by: | ryandesign (Ryan Carsten Schmidt) |
---|---|---|---|
Priority: | Normal | Milestone: | |
Component: | ports | Version: | 2.3.4 |
Keywords: | haspatch | Cc: | mopihopi |
Port: | ImageMagick |
Description
ImageMagick has a serious security issue (CVE-2016-3714). Update to 6.9.3-9 attached.
BTW: ImageMagick 6.9.3-9 is now the legacy version. ImageMagick 7.0.1 is current.
Attachments (1)
Change History (7)
Changed 9 years ago by Schamschula (Marius Schamschula)
Attachment: | Portfile-ImageMagick.diff added |
---|
comment:1 Changed 9 years ago by ryandesign (Ryan Carsten Schmidt)
Status: | new → assigned |
---|
comment:2 Changed 9 years ago by ryandesign (Ryan Carsten Schmidt)
Resolution: | → fixed |
---|---|
Status: | assigned → closed |
comment:3 Changed 9 years ago by mopihopi
Resolution: | fixed |
---|---|
Status: | closed → reopened |
According to the announcement https://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=29588 the security issue was fixed in ImageMagick 7.0.1-1 and 6.9.3-10. However this patch upgrades to 6.9.3-9. Should this be upgraded to 6.9.3-10? Also what is needed to update to the current version 7.0.1-1?
comment:4 Changed 9 years ago by ryandesign (Ryan Carsten Schmidt)
Cc: | mopihopi@… added |
---|
6.9.3-10 did not exist when I resolved this ticket. Marius asked me to update the port to 6.9.3-9. I verified it built and installed successfully on my system. I verified that no newer version of 6.9.3 existed. I committed the update. Now 6.9.3-10 has been released with new fixes, and I'm happy to update the port to that version as well, but in the future, please file a new ticket when there is a new issue.
I have not yet looked into what is involved with updating to ImageMagick 7. I'm happy to look into that, when I have a little more time, if you file a new ticket for that.
comment:5 Changed 9 years ago by ryandesign (Ryan Carsten Schmidt)
Resolution: | → fixed |
---|---|
Status: | reopened → closed |
comment:6 Changed 9 years ago by mopihopi
Thanks! I have filed a new ticket for updating to 7.0.1-1 (#51310).
Thanks.