[magick-users] Security flaw fixed, ImageMagick 6.2.9-5 released

quetzlzacatenango at imagemagick.org quetzlzacatenango at imagemagick.org
Tue Sep 12 20:43:06 CDT 2006


We're releasing ImageMagick 6.2.9-5 to fix a security flaw.  It will mirror
worldwide this evening and will be available by tommorrow.  Here is the
ChangeLog:

2006-09-11  6.2.9-5 Cristy  <quetzlzacatenango at image...>
  * Improve -monochrome option.
  * %% now works in output image filename (reference
    http://redux.imagemagick.org/discussion-server/viewtopic.php?p=22393).
  * Install check to ensure the blob offset is less than the blob length in
    ReadBlob() to prevent accidental or malicious buffer overflow (reference
    [AD_LAB-06010]).



More information about the Magick-users mailing list