Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 9: DLA-2366-1 Critical: Imagemagick Memory Exploits

debian lts
Calendar Grey September 7, 2020
Dist Debian Esm H88
Ubuntu Security Notice USN-4717-1 fixes various vulnerabilities in libjpeg-turbo, which could lead to unauthorized access and potential system crashes.
Debian Bug : 870020 870019 876105 869727 886281 873059 870504 870530 870107 872609 875338 875339 875341 873871 873131 875352 878506 875503 875502 876105 876099 878546 878545 877354...

Summary

Several security vulnerabilities were found in Imagemagick. Various
memory handling problems and cases of missing or incomplete input
sanitizing may result in denial of service, memory or CPU exhaustion,
information disclosure or potentially the execution of arbitrary code
when a malformed image file is processed.

For Debian 9 stretch, these problems have been fixed in version
8:6.9.7.4+dfsg-11+deb9u10.

We recommend that you upgrade your imagemagick packages.

For the detailed security status of imagemagick please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/imagemagick

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: imagemagick
Version: 8:6.9.7.4+dfsg-11+deb9u10
CVE ID: CVE-2017-12140 CVE-2017-12429 CVE-2017-12430
Debian Bug: 870020 870019 876105 869727 886281 873059 870504

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here