Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian 7 DLA-953-1 Critical: GraphicsMagick Information Leak

debian lts
Calendar Grey May 26, 2017
Dist Debian Esm H88
Important patch released for graphicsmagick addressing memory leaks that can lead to data exposure in Debian 7.
Chris Evans discovered that graphicsmagick used uninitialized memory in the RLE decoder, allowing an remote attacker to leak sensitive information from process memory space

Summary

More information are available at:
https://scarybeastsecurity.blogspot.com/2017/05/bleed-continues-18-byte-file-14k-bounty.html

For Debian 7 "Wheezy", these problems have been fixed in version
1.3.16-1.1+deb7u7.

We recommend that you upgrade your graphicsmagick packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: graphicsmagick
Version: 1.3.16-1.1+deb7u7
CVE ID: CVE-2017-9098
Debian Bug: 862967

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here