From f4f9edc7423863e957af0fc18a1efc4dd2417cc2 Mon Sep 17 00:00:00 2001 From: Funda Wang Date: Sun, 19 Oct 2025 20:26:16 +0800 Subject: [PATCH] 7.1.2-7 (cherry picked from commit c75172bba8656e6a31b39e0e2d0aba9a0e10d41a) --- .gitattributes | 1 + CVE-2025-57807.patch | 42 ------------------- ...1.2-2.tar.gz => ImageMagick-7.1.2-7.tar.xz | 4 +- ImageMagick.spec | 13 +++--- 4 files changed, 11 insertions(+), 49 deletions(-) delete mode 100644 CVE-2025-57807.patch rename ImageMagick-7.1.2-2.tar.gz => ImageMagick-7.1.2-7.tar.xz (32%) diff --git a/.gitattributes b/.gitattributes index f087b42..354881a 100644 --- a/.gitattributes +++ b/.gitattributes @@ -1 +1,2 @@ *.tar.gz filter=lfs diff=lfs merge=lfs -text +*.xz filter=lfs diff=lfs merge=lfs -text diff --git a/CVE-2025-57807.patch b/CVE-2025-57807.patch deleted file mode 100644 index 0b000ff..0000000 --- a/CVE-2025-57807.patch +++ /dev/null @@ -1,42 +0,0 @@ -From 077a417a19a5ea8c85559b602754a5b928eef23e Mon Sep 17 00:00:00 2001 -From: Cristy -Date: Sun, 24 Aug 2025 12:32:18 -0400 -Subject: [PATCH] - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-23hg-53q6-hqfg - ---- - MagickCore/blob.c | 11 +++++++---- - 1 file changed, 7 insertions(+), 4 deletions(-) - -diff --git a/MagickCore/blob.c b/MagickCore/blob.c -index dfd489d3afc..20082336a45 100644 ---- a/MagickCore/blob.c -+++ b/MagickCore/blob.c -@@ -1630,7 +1630,7 @@ static inline ssize_t WriteBlobStream(Image *image,const size_t length, - extent=(MagickSizeType) (blob_info->offset+(MagickOffsetType) length); - if (extent >= blob_info->extent) - { -- extent=blob_info->extent+blob_info->quantum+length; -+ extent+=blob_info->quantum+length; - blob_info->quantum<<=1; - if (SetBlobExtent(image,extent) == MagickFalse) - return(0); -@@ -5912,12 +5912,15 @@ MagickExport ssize_t WriteBlob(Image *image,const size_t length, - } - case BlobStream: - { -- if ((blob_info->offset+(MagickOffsetType) length) >= -- (MagickOffsetType) blob_info->extent) -+ MagickSizeType -+ extent; -+ -+ extent=(MagickSizeType) (blob_info->offset+(MagickOffsetType) length); -+ if (extent >= blob_info->extent) - { - if (blob_info->mapped != MagickFalse) - return(0); -- blob_info->extent+=length+blob_info->quantum; -+ blob_info->extent=extent+blob_info->quantum+length; - blob_info->quantum<<=1; - blob_info->data=(unsigned char *) ResizeQuantumMemory( - blob_info->data,blob_info->extent+1,sizeof(*blob_info->data)); diff --git a/ImageMagick-7.1.2-2.tar.gz b/ImageMagick-7.1.2-7.tar.xz similarity index 32% rename from ImageMagick-7.1.2-2.tar.gz rename to ImageMagick-7.1.2-7.tar.xz index d310025..a26165c 100644 --- a/ImageMagick-7.1.2-2.tar.gz +++ b/ImageMagick-7.1.2-7.tar.xz @@ -1,3 +1,3 @@ version https://git-lfs.github.com/spec/v1 -oid sha256:f511deb5827b07906e0558640a436a96644949dfd6bb21b1a641b09690ac3bdc -size 15719110 +oid sha256:9bcbd4b70f70c9592307e19e875f5ec147e2a84ae9a36a297a76cafff18308d4 +size 10795132 diff --git a/ImageMagick.spec b/ImageMagick.spec index 15c1f3a..368b6b7 100644 --- a/ImageMagick.spec +++ b/ImageMagick.spec @@ -1,14 +1,13 @@ Name: ImageMagick Epoch: 1 -Version: 7.1.2.2 -Release: 2 +Version: 7.1.2.7 +Release: 1 Summary: Create, edit, compose, or convert bitmap images License: ImageMagick and MIT -Url: http://www.imagemagick.org/ +Url: https://www.imagemagick.org/ %global VER %(foo=%{version}; echo ${foo:0:5}) %global Patchlevel %(foo=%{version}; echo ${foo:6}) -Source0: https://github.com/ImageMagick/ImageMagick/archive/%{VER}-%{Patchlevel}/%{name}-%{VER}-%{Patchlevel}.tar.gz -Patch0: CVE-2025-57807.patch +Source0: https://imagemagick.org/archive/releases/%{name}-%{VER}-%{Patchlevel}.tar.xz BuildRequires: bzip2-devel freetype-devel libjpeg-devel libpng-devel perl-generators BuildRequires: libtiff-devel giflib-devel zlib-devel perl-devel >= 5.8.1 jbigkit-devel @@ -43,6 +42,7 @@ Development files for ImageMagick. %package help Summary: HTML documentation for ImageMagick +Buildarch: noarch Provides: ImageMagick-doc = %{epoch}:%{version}-%{release} Obsoletes: ImageMagick-doc < %{epoch}:%{version}-%{release} @@ -162,6 +162,9 @@ rm PerlMagick/demo/Generic.ttf %{_libdir}/pkgconfig/ImageMagick* %changelog +* Wed Oct 15 2025 Funda Wang - 1:7.1.2.7-1 +- update to 7.1.2-7 + * Mon Sep 08 2025 yaoxin <1024769339@qq.com> - 1:7.1.2.2-2 - Fix CVE-2025-57807 -- Gitee