Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Fedora 25: 2017-66d9113c7a Critical: RUBYGEM-RMAGICK NULL Pointer Risk

fedora
Calendar Grey October 11, 2017
Dist Fedora Esm H88
Tackling vulnerabilities within the rubygem-rmagick concerning obsolete ImageMagick directories and a severe NULL pointer dereference.
6.9.9-15 ---- Rebuilt for ImageMagick 6.9.9-13

Summary

RMagick is an interface between Ruby and ImageMagick.

6.9.9-15 ---- Rebuilt for ImageMagick 6.9.9-13

[ 1 ] Bug #1496308 - [config/type-ghostscript.xml.in] using outdated hardcoded paths for (URW)++ fonts

https://bugzilla.redhat.com/show_bug.cgi?id=1496308

[ 2 ] Bug #1496032 - convert: Ignoring invalid time value

https://bugzilla.redhat.com/show_bug.cgi?id=1496032

[ 3 ] Bug #1487680 - CVE-2017-13768 ImageMagick: NULL pointer dereference in IdentifyImage function in MagickCore/identify.c [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1487680

su -c 'dnf upgrade rubygem-rmagick' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 25
Version: 2.16.0
Release: 7.fc25
Summary: Ruby binding to ImageMagick

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here