USN-784-1: ImageMagick vulnerability

Publication date

8 June 2009

Overview

ImageMagick vulnerability


Packages

Details

It was discovered that ImageMagick did not properly verify the dimensions
of TIFF files. If a user or automated system were tricked into opening a
crafted TIFF file, an attacker could cause a denial of service or possibly
execute arbitrary code with the privileges of the user invoking the
program.

It was discovered that ImageMagick did not properly verify the dimensions
of TIFF files. If a user or automated system were tricked into opening a
crafted TIFF file, an attacker could cause a denial of service or possibly
execute arbitrary code with the privileges of the user invoking the
program.

Update instructions

In general, a standard system upgrade is sufficient to effect the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
9.04 jaunty libmagickcore1 –  7:6.4.5.4.dfsg1-1ubuntu3.1
8.10 intrepid libmagick10 –  7:6.3.7.9.dfsg1-2ubuntu3.1
8.04 hardy libmagick10 –  7:6.3.7.9.dfsg1-2ubuntu1.1
6.06 dapper libmagick9 –  6:6.2.4.5-0.6ubuntu0.9

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›