Created attachment 177008 [details] Bump ImageMagick to 6.9.6-4 Please bump ImageMagick to latest version, 6.9.6-4. Summarized changelog since 6.9.5-10: * Off by one memory allocation (reference https://github.com/ImageMagick/ImageMagick/issues/296). * Prevent fault in MSL interpreter (reference https://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=30797). * Added layer ZIP compression to the PSD encoder. * Unit test pass again after small SUN image patch. * Fixed incorrect RLE decoding when reading a DCM image that contains multiple segments. * Fixed incorrect RLE decoding when reading an SGI image (reference https://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=30514) Fixes CVE-2016-9298 (upstream issue 296). Passes Poudriere build test for 11.0 amd64, both ImageMagick and ImageMagick-nox11. Currently testing 10.3 and 9.3.
Poudriere builds passed for 10.3 and 9.3, amd64.
A commit references this bug: Author: feld Date: Mon Dec 5 00:07:34 UTC 2016 New revision: 427821 URL: https://svnweb.freebsd.org/changeset/ports/427821 Log: graphics/ImageMagick: Update to 6.9.6-4 Summarized changelog since 6.9.5-10: * Off by one memory allocation (reference https://github.com/ImageMagick/ImageMagick/issues/296). * Prevent fault in MSL interpreter (reference https://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=30797). * Added layer ZIP compression to the PSD encoder. * Unit test pass again after small SUN image patch. * Fixed incorrect RLE decoding when reading a DCM image that contains multiple segments. * Fixed incorrect RLE decoding when reading an SGI image (reference https://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=30514) PR: 214517 MFH: 2016Q4 Security: CVE-2016-9298 Changes: head/graphics/ImageMagick/Makefile head/graphics/ImageMagick/distinfo head/graphics/ImageMagick/pkg-plist
A commit references this bug: Author: feld Date: Mon Dec 5 00:08:23 UTC 2016 New revision: 427822 URL: https://svnweb.freebsd.org/changeset/ports/427822 Log: MFH: r427821 graphics/ImageMagick: Update to 6.9.6-4 Summarized changelog since 6.9.5-10: * Off by one memory allocation (reference https://github.com/ImageMagick/ImageMagick/issues/296). * Prevent fault in MSL interpreter (reference https://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=30797). * Added layer ZIP compression to the PSD encoder. * Unit test pass again after small SUN image patch. * Fixed incorrect RLE decoding when reading a DCM image that contains multiple segments. * Fixed incorrect RLE decoding when reading an SGI image (reference https://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=30514) PR: 214517 Security: CVE-2016-9298 Approved by: ports-secteam (with hat) Changes: _U branches/2016Q4/ branches/2016Q4/graphics/ImageMagick/Makefile branches/2016Q4/graphics/ImageMagick/distinfo branches/2016Q4/graphics/ImageMagick/pkg-plist