package/imagemagick: security bump to version 7.0.8-42
authorPeter Korsgaard <peter@korsgaard.com>
Mon, 29 Apr 2019 21:34:48 +0000 (23:34 +0200)
committerPeter Korsgaard <peter@korsgaard.com>
Tue, 30 Apr 2019 11:17:09 +0000 (13:17 +0200)
commit43ff6b974c6a5d07a705ebbdfdb7cd11ecff9c4c
treeb7c6fccf5223d92886af77eb099b2ba07214df78
parent94c6cab917c79334136cb74409eab9bc2f240677
package/imagemagick: security bump to version 7.0.8-42

Fixes the following security issues:

- CVE-2019-9956: In ImageMagick 7.0.8-35 Q16, there is a stack-based buffer
  overflow in the function PopHexPixel of coders/ps.c, which allows an
  attacker to cause a denial of service or code execution via a crafted
  image file.

- CVE-2019-10650: In ImageMagick 7.0.8-36 Q16, there is a heap-based buffer
  over-read in the function WriteTIFFImage of coders/tiff.c, which allows an
  attacker to cause a denial of service or information disclosure via a
  crafted image file.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/imagemagick/imagemagick.hash
package/imagemagick/imagemagick.mk