Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Fri, 20 May 2016 14:54:45 +0200
From: Sven Kieske <>
To: <>
Subject: Re: ImageMagick Is On Fire -- CVE-2016-3714

On 19/05/16 19:07, Bob Friesenhahn wrote:
> As an example Ubuntu 14.04.4 LTS (which is supposed to be getting
> security updates) has not provided ImageMagick or GraphicsMagick
> package updates in 3 years.


as you can see here:

GM in Ubuntu resides in the "universe" repository

When you read up about "universe" here:

you will see that:

"Universe - Community maintained software, i.e. not officially supported

which means all software from universe is _not_ officially supported
by canonical and thus receives only timely updates, if a community
member picks up the necessary work.

Too also quote from

"The LTS designation applies only to specific subsets of the Ubuntu

See also this (german) article about packages which do not
get security updates in Ubuntu "LTS" releases, because they are
only community maintained:

There is also a command line tool to find out about unsupported

ubuntu-support-status --show-unsupported


Mit freundlichen Grüßen / Regards

Sven Kieske

Mittwald CM Service GmbH & Co. KG
Königsberger Straße 6
32339 Espelkamp
T: +495772 293100
F: +495772 293333
Geschäftsführer: Robert Meyer
St.Nr.: 331/5721/1033, USt-IdNr.: DE814773217, HRA 6640, AG Bad Oeynhausen
Komplementärin: Robert Meyer Verwaltungs GmbH, HRB 13260, AG Bad Oeynhausen

Download attachment "signature.asc" of type "application/pgp-signature" (837 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.