Alerts This Week
Warning Icon 1 1,149
Alerts This Week
Warning Icon 1 1,149

Ubuntu 22.04 LTS USN-6200-2 Moderate: ImageMagick Memory Threat

ubuntu
Calendar Grey August 5, 2024
Dist Ubuntu Esm H88
This notice highlights various security patches, targeting denial of service weaknesses in ImageMagick on Ubuntu platforms.
Several security issues were fixed in ImageMagick.

Summary

Several security issues were fixed in ImageMagick.

Software Description:

- imagemagick: Image manipulation programs and library

Details:

USN-6200-1 fixed vulnerabilities in ImageMagick. Unfortunately these fixes were

incomplete for Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. This update fixes the

problem.

Original advisory details:

It was discovered that ImageMagick incorrectly handled the "-authenticate"

option for password-protected PDF files. An attacker could possibly use

this issue to inject additional shell commands and perform arbitrary code

execution. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-29599)

It was discovered that ImageMagick incorrectly handled certain values

when processing PDF files. If a user or automated system using ImageMagick

were tricked into opening a specially crafted PDF file, an attacker could

exploit this to cause a denial of service. This issue only affected Ubuntu

20.04 LTS. (CVE-2021-20224)

Zhang Xi...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS
  imagemagick                     8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  imagemagick-6-common            8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  imagemagick-6.q16               8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  imagemagick-6.q16hdri           8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  imagemagick-common              8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  libimage-magick-perl            8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  libimage-magick-q16-perl        8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  libimage-magick-q16hdri-perl    8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  libmagick++-6-headers           8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  libmagick++-6.q16-8             8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  libmagick++-6.q16-dev           8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  libmagick++-6.q16hdri-8         8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  libmagick++-6.q16hdri-dev       8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  libmagick++-dev                 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  libmagickcore-6-headers         8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  libmagickcore-6.q16-6           8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  libmagickcore-6.q16-dev         8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  libmagickcore-6.q16hdri-6       8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  libmagickcore-6.q16hdri-dev     8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  libmagickcore-dev               8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  libmagickwand-6-headers         8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  libmagickwand-6.q16-6           8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  libmagickwand-6.q16-dev         8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  libmagickwand-6.q16hdri-6       8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  libmagickwand-6.q16hdri-dev     8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  libmagickwand-dev               8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
  perlmagick                      8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5

Ubuntu 20.04 LTS
  imagemagick                     8:6.9.10.23+dfsg-2.1ubuntu11.10
  imagemagick-6-common            8:6.9.10.23+dfsg-2.1ubuntu11.10
  imagemagick-6.q16               8:6.9.10.23+dfsg-2.1ubuntu11.10
  imagemagick-6.q16hdri           8:6.9.10.23+dfsg-2.1ubuntu11.10
  imagemagick-common              8:6.9.10.23+dfsg-2.1ubuntu11.10
  libimage-magick-perl            8:6.9.10.23+dfsg-2.1ubuntu11.10
  libimage-magick-q16-perl        8:6.9.10.23+dfsg-2.1ubuntu11.10
  libimage-magick-q16hdri-perl    8:6.9.10.23+dfsg-2.1ubuntu11.10
  libmagick++-6-headers           8:6.9.10.23+dfsg-2.1ubuntu11.10
  libmagick++-6.q16-8             8:6.9.10.23+dfsg-2.1ubuntu11.10
  libmagick++-6.q16-dev           8:6.9.10.23+dfsg-2.1ubuntu11.10
  libmagick++-6.q16hdri-8         8:6.9.10.23+dfsg-2.1ubuntu11.10
  libmagick++-6.q16hdri-dev       8:6.9.10.23+dfsg-2.1ubuntu11.10
  libmagick++-dev                 8:6.9.10.23+dfsg-2.1ubuntu11.10
  libmagickcore-6-headers         8:6.9.10.23+dfsg-2.1ubuntu11.10
  libmagickcore-6.q16-6           8:6.9.10.23+dfsg-2.1ubuntu11.10
  libmagickcore-6.q16-dev         8:6.9.10.23+dfsg-2.1ubuntu11.10
  libmagickcore-6.q16hdri-6       8:6.9.10.23+dfsg-2.1ubuntu11.10
  libmagickcore-6.q16hdri-dev     8:6.9.10.23+dfsg-2.1ubuntu11.10
  libmagickcore-dev               8:6.9.10.23+dfsg-2.1ubuntu11.10
  libmagickwand-6-headers         8:6.9.10.23+dfsg-2.1ubuntu11.10
  libmagickwand-6.q16-6           8:6.9.10.23+dfsg-2.1ubuntu11.10
  libmagickwand-6.q16-dev         8:6.9.10.23+dfsg-2.1ubuntu11.10
  libmagickwand-6.q16hdri-6       8:6.9.10.23+dfsg-2.1ubuntu11.10
  libmagickwand-6.q16hdri-dev     8:6.9.10.23+dfsg-2.1ubuntu11.10
  libmagickwand-dev               8:6.9.10.23+dfsg-2.1ubuntu11.10
  perlmagick                      8:6.9.10.23+dfsg-2.1ubuntu11.10

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6200-2

https://ubuntu.com/security/notices/USN-6200-1

CVE-2023-1289, CVE-2023-34151

Ubuntu Security Notice USN-6200-2

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here