Tavis Ormandy discovered a format string vulnerability in the
filename handling code which allows a remote attacker to cause a
denial of service and possibly execute arbitrary code.
CAN-2005-0759
Andrei Nigmatulin discovered a denial of service condition which
can be caused by an invalid tag in a TIFF image.
CAN-2005-0760
Andrei Nigmatulin discovered that the TIFF decoder is vulnerable
to accessing memory out of bounds which will result in a
segmentation fault.
CAN-2005-0762
Andrei Nigmatulin discovered a buffer overflow in the SGI parser
which allows a remote attacker to execute arbitrary code via a
specially crafted SGI image file.
For the stable distribution (woody) these problems have been fixed in
version 5.4.4.5-1woody6.
For the unstable distribution (sid) these problems have been fixed in
version 6.0.6.2-2.2.
We recommend that you upgrade your imagemagick package.
Upgrade Instructions
- --------------------wget url
...
Get the latest Linux and open source security news straight to your inbox.