Get the LinuxSecurity news you want faster with RSS
Powered By
Pardus: Imagemagick: Multiple
Posted by Benjamin D. Thomas
exploited by malicious people to potentially compromise a user's system.
--==============23883774=Content-Type: multipart/alternative; boundary 16e6d27ed1c6a055046d177296
--0016e6d27ed1c6a055046d177296
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
------------------------------------------------------------------------
Pardus Linux Security Advisory 2009-90 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2009-06-24
Severity: 3
Type: Remote
------------------------------------------------------------------------
Summary
======
Tielei Wang has discovered a vulnerability in ImageMagick, which can be
exploited by malicious people to potentially compromise a user's system.
Description
==========
The vulnerability is caused due to an integer overflow error within the
"XMakeImage()" function in magick/xwindow.c. This can be exploited to
cause a buffer overflow via e.g. a specially crafted TIFF file.
Successful exploitation may allow execution of arbitrary code.
Affected packages:
Pardus 2008:
imagemagick, all before 6.4.4.10-25-9
Resolution
=========
There are update(s) for imagemagick. You can update them via Package
Manager or with a single command from console:
pisi up imagemagick
References
=========
* http://bugs.pardus.org.tr/show_bug.cgi?id˜42
* http://www.imagemagick.org/script/changelog.php
* http://secunia.com/advisories/35216/