Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian 7 LTS DLA-1139-1 Critical: ImageMagick DoS And Disclosure Issues

debian lts
Calendar Grey October 19, 2017
Dist Debian Esm H88
Recent patch resolves significant vulnerabilities in ImageMagick, effectively mitigating DoS threats and information leakage concerns.
This update fixes two vulnerabilities in ImageMagick: CVE-2017-15277

Summary

CVE-2017-15277

An uninitialized data structure could lead to information disclosure
when reading a specially crafted GIF file.

CVE-2017-15281

An uninitialized value used in a conditional jump could cause a
denial of service (application crash) or other unspecified impacts
when reading a specially crafted PSD file.

For Debian 7 "Wheezy", these problems have been fixed in version
8:6.7.7.10-5+deb7u18.

We recommend that you upgrade your imagemagick packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

<pre><font face="Courier">Package: imagemagick
Version: 8:6.7.7.10-5+deb7u18
CVE ID: CVE-2017-15277 CVE-2017-15281
Debian Bug: 878578 878579

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here