Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian 8 DSA-3746-1 Critical: GraphicsMagick Denial Of Service Threat

debian
Calendar Grey December 24, 2016
Debian Logo
New release of GraphicsMagick third-party library issued to tackle various security vulnerabilities and enhance the protection of systems.
Several vulnerabilities have been discovered in GraphicsMagick, a collection of image processing tool, which can cause denial of service attacks, remote file deletion, and remote c...

Summary

This security update removes the full support of PLT/Gnuplot decoder to
prevent Gnuplot-shell based shell exploits for fixing the CVE-2016-3714
vulnerability.

The undocumented "TMP" magick prefix no longer removes the argument file
after it has been read for fixing the CVE-2016-3715 vulnerability. Since
the "TMP" feature was originally implemented, GraphicsMagick added a
temporary file management subsystem which assures that temporary files
are removed so this feature is not needed.

Remove support for reading input from a shell command, or writing output
to a shell command, by prefixing the specified filename (containing the
command) with a '|' for fixing the CVE-2016-5118 vulnerability.

CVE-2015-8808

Gustavo Grieco discovered an out of bound read in the parsing of GIF
files which may cause denial of service.

CVE-2016-2317

Gustavo Grieco discovered a stack buffer overflow and two heap buffer
overflows while processing SVG images which may cause denial of service.

CVE-2016-2318

Gus...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: graphicsmagick
CVE ID: CVE-2015-8808 CVE-2016-2317 CVE-2016-2318 CVE-2016-3714

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here