8:6.8.9.9-7ubuntu5.13 breaks convert with no explanation
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
imagemagick (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned |
Bug Description
8:6.8.9.
$ convert -density 200 -quality 40 null: 10-07-dvla.pdf 10-07-dvla.jpg
convert: not authorized `10-07-dvla.pdf' @ error/constitut
I appreciate that this is likely a security fix for something, but I can find no useful information in the changelog.Debian or NEWS files on what has changed, and what I should do to restore previous functionality.
ProblemType: Bug
DistroRelease: Ubuntu 16.04
Package: imagemagick 8:6.8.9.
ProcVersionSign
Uname: Linux 4.15.0-33-generic x86_64
NonfreeKernelMo
ApportVersion: 2.20.1-0ubuntu2.18
Architecture: amd64
CurrentDesktop: XFCE
Date: Sun Oct 7 14:35:08 2018
InstallationDate: Installed on 2017-01-08 (637 days ago)
InstallationMedia: Xubuntu 16.04 LTS "Xenial Xerus" - Release amd64 (20160420.1)
SourcePackage: imagemagick
UpgradeStatus: No upgrade log present (probably fresh install)
tags: | added: regression-security |
The package changelog mentions this:
* SECURITY UPDATE: code execution vulnerabilities in ghostscript as patches/ 200-disable- ghostscript- formats. patch: disable
invoked by imagemagick
- debian/
ghostscript handled types by default in policy.xml
https:/ /bugs.launchpad .net/ubuntu/ +source/ imagemagick/ 8:6.8.9. 9-7ubuntu5. 13