Linux Security
    Linux Security
    Linux Security

    Debian: DSA-2427-1: imagemagick security update

    Date 06 Mar 2012
    202
    Posted By LinuxSecurity Advisories
    Two security vulnerabilities related to EXIF processing were discovered in ImageMagick, a suite of programs to manipulate images: CVE-2012-0247
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - -------------------------------------------------------------------------
    Debian Security Advisory DSA-2427-1                   This email address is being protected from spambots. You need JavaScript enabled to view it.
    https://www.debian.org/security/                            Florian Weimer
    March 06, 2012                         https://www.debian.org/security/faq
    - -------------------------------------------------------------------------
    
    Package        : imagemagick
    Vulnerability  : several
    Problem type   : local
    CVE ID         : CVE-2012-0247 CVE-2012-0248
    
    Two security vulnerabilities related to EXIF processing were
    discovered in ImageMagick, a suite of programs to manipulate images:
    
    CVE-2012-0247
    	When parsing a maliciously crafted image with incorrect offset
    	and count in the ResolutionUnit tag in EXIF IFD0, ImageMagick
    	writes two bytes to an invalid address.
    
    CVE-2012-0248
    	Parsing a maliciously crafted image with an IFD whose all IOP
    	tags value offsets point to the beginning of the IFD itself
    	results in an endless loop and a denial of service.
    
    For the stable distribution (squeeze), these problems have been fixed
    in version 8:6.6.0.4-3+squeeze1.
    
    For the testing distribution (wheezy) and the unstable distribution
    (sid), these problems have been fixed in version 8:6.6.9.7-6.
    
    We recommend that you upgrade your imagemagick packages.
    
    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/
    
    Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it.
    

    Advisories

    LinuxSecurity Poll

    No results found.

    Please enable / Bitte aktiviere JavaScript!
    Veuillez activer / Por favor activa el Javascript![ ? ]

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.