diff --git a/0001-fix-CVE-2025-55005.patch b/0001-fix-CVE-2025-55005.patch new file mode 100644 index 0000000000000000000000000000000000000000..9a3ec8c21ed4c3194ec611a249f82ab3b7cfaa47 --- /dev/null +++ b/0001-fix-CVE-2025-55005.patch @@ -0,0 +1,34 @@ +From 52df183490e315987234a6eeb5ece1aa87b5dbb2 Mon Sep 17 00:00:00 2001 +From: HouHongxun +Date: Tue, 14 Oct 2025 13:47:18 +0800 +Subject: [PATCH] fix CVE-2025-55005 + +Signed-off-by: HouHongxun +--- + magick/colorspace.c | 6 ++++++ + 1 file changed, 6 insertions(+) + +diff --git a/magick/colorspace.c b/magick/colorspace.c +index 7f34fde..48de47e 100644 +--- a/magick/colorspace.c ++++ b/magick/colorspace.c +@@ -2425,10 +2425,16 @@ MagickExport MagickBooleanType TransformRGBImage(Image *image, + value=GetImageProperty(image,"reference-black"); + if (value != (const char *) NULL) + reference_black=StringToDouble(value,(char **) NULL); ++ if (reference_black > MaximumLogarithmicColorspace) ++ reference_black=MaximumLogarithmicColorspace; + reference_white=ReferenceWhite; + value=GetImageProperty(image,"reference-white"); + if (value != (const char *) NULL) + reference_white=StringToDouble(value,(char **) NULL); ++ if (reference_white > MaximumLogarithmicColorspace) ++ reference_white=MaximumLogarithmicColorspace; ++ if (reference_black > reference_white) ++ reference_black=reference_white; + logmap=(Quantum *) AcquireQuantumMemory((size_t) MaxMap+1UL, + sizeof(*logmap)); + if (logmap == (Quantum *) NULL) +-- +2.27.0 + diff --git a/ImageMagick.spec b/ImageMagick.spec index ee8d78e54f81fbfe00b7a775e2a9be0e6bc9696b..9527eb9f73c84dd20419065f5806da6eba98eaed 100644 --- a/ImageMagick.spec +++ b/ImageMagick.spec @@ -1,13 +1,14 @@ Name: ImageMagick Epoch: 1 Version: 6.9.13.32 -Release: 1 +Release: 2 Summary: Create, edit, compose, or convert bitmap images License: ImageMagick and MIT Url: http://www.imagemagick.org/ %global VER %(foo=%{version}; echo ${foo:0:6}) %global Patchlevel %(foo=%{version}; echo ${foo:7}) Source0: https://download.imagemagick.org/archive/%{name}-%{VER}-%{Patchlevel}.tar.xz +Patch0: 0001-fix-CVE-2025-55005.patch BuildRequires: bzip2-devel freetype-devel libjpeg-devel libpng-devel perl-generators BuildRequires: libtiff-devel giflib-devel zlib-devel perl-devel >= 5.8.1 jbigkit-devel @@ -165,6 +166,9 @@ rm PerlMagick/demo/Generic.ttf %{_libdir}/pkgconfig/ImageMagick++* %changelog +* Mon Nov 24 2025 gongxingliang - 1:6.9.13.32-2 +- Fix CVE-2025-55005 + * Sun Oct 19 2025 Funda Wang - 1:6.9.13.32-1 - update to 6.9.13.32 for fix CVE-2025-62171