Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 20.04 LTS USN-5974-1 Moderate: GraphicsMagick Heap Overflow

ubuntu
Calendar Grey March 27, 2023
Scroller Ubuntu
Crucial security flaws addressed in GraphicsMagick for multiple Ubuntu LTS editions. Protect your setup promptly.
Several security issues were fixed in GraphicsMagick.

Summary

Several security issues were fixed in GraphicsMagick.

Software Description:

- graphicsmagick: collection of image processing tools

Details:

It was discovered that GraphicsMagick was not properly performing bounds

checks when processing TGA image files, which could lead to a heap buffer

overflow. If a user or automated system were tricked into processing a

specially crafted TGA image file, an attacker could possibly use this

issue to cause a denial of service or execute arbitrary code. This issue

only affected Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. (CVE-2018-20184)

It was discovered that GraphicsMagick was not properly validating bits per

pixel data when processing DIB image files. If a user or automated system

were tricked into processing a specially crafted DIB image file, an

attacker could possibly use this issue to cause a denial of service. This

issue only affected Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.

(CVE-2018-20189)

It was discovered that Graphics...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
   graphicsmagick                  1.4+really1.3.35-1ubuntu0.1
   libgraphicsmagick-q16-3         1.4+really1.3.35-1ubuntu0.1

Ubuntu 18.04 LTS:
   graphicsmagick                  1.3.28-2ubuntu0.2+esm1
   libgraphicsmagick-q16-3         1.3.28-2ubuntu0.2+esm1

Ubuntu 16.04 ESM:
   graphicsmagick                  1.3.23-1ubuntu0.6+esm2
   libgraphicsmagick-q16-3         1.3.23-1ubuntu0.6+esm2

Ubuntu 14.04 ESM:
   graphicsmagick                  1.3.18-1ubuntu3.1+esm8
   libgraphicsmagick3              1.3.18-1ubuntu3.1+esm8

In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-5974-1

  CVE-2018-20184, CVE-2018-20189, CVE-2018-5685, CVE-2018-9018,

  CVE-2019-11006, CVE-2020-12672, CVE-2022-1270

Severity
important
Lowest
Low
Medium
High
Critical

March 27, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.