[arch-security] [ASA-201501-1] imagemagick: multiple issues

Remi Gacogne rgacogne at archlinux.org
Wed Jan 7 08:45:26 UTC 2015


Arch Linux Security Advisory ASA-201501-1
=========================================

Severity: High
Date    : 2015-01-07
CVE-ID  :
Package : imagemagick
Type    : multiple issues
Remote  : No
Link    : https://wiki.archlinux.org/index.php/CVE-2014

Summary
=======

The package imagemagick before version 6.9.0.3-1 is vulnerable to
multiple issues, including denial of service and arbitrary code execution.

Resolution
==========

Upgrade to 6.9.0.3-1.

# pacman -Syu "imagemagick>=6.9.0.3-1"

The problem has been fixed upstream in version 6.9.0.3.

Workaround
==========

None.

Description
===========

Numerous vulnerabilities, including but not limited to buffer overflow,
out-of-bound read, double-free and user-after-free have been fixed in
imagemagick 6.9.0.2 and 6.9.0.3.

Impact
======

An attacker allowed to supply a specially crafted image to imagemagick
will be able to crash the process and execute arbitrary code.

References
==========

http://www.openwall.com/lists/oss-security/2014/12/24/1
http://osvdb.org/show/osvdb/116399
http://osvdb.org/show/osvdb/116397
http://osvdb.org/show/osvdb/116396
http://osvdb.org/show/osvdb/116395
http://osvdb.org/show/osvdb/116394
http://osvdb.org/show/osvdb/116394
http://osvdb.org/show/osvdb/116385
http://osvdb.org/show/osvdb/116389
http://osvdb.org/show/osvdb/116388
http://osvdb.org/show/osvdb/116386
http://osvdb.org/show/osvdb/116368
http://osvdb.org/show/osvdb/116359

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: OpenPGP digital signature
URL: <https://lists.archlinux.org/pipermail/arch-security/attachments/20150107/a3cf5183/attachment.bin>


More information about the arch-security mailing list