Alerts This Week
Warning Icon 1 1,053
Alerts This Week
Warning Icon 1 1,053

Ubuntu 14.04 LTS USN-6980-1: ImageMagick Denial of Service Advisory

ubuntu
Calendar Grey August 22, 2024
Dist Ubuntu Esm H88
Recent patches for Ubuntu 14.04 address multiple vulnerabilities in ImageMagick. Learn about the specific vulnerabilities fixed and the updates provided.
Several security issues were fixed in ImageMagick.

Summary

Several security issues were fixed in ImageMagick.

Software Description:

- imagemagick: Image manipulation programs and library

Details:

It was discovered that ImageMagick incorrectly handled certain malformed

image files. If a user or automated system using ImageMagick were tricked

into opening a specially crafted image, an attacker could exploit this to

cause a denial of service or possibly execute code with the privileges of

the user invoking the program.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS
   imagemagick                     8:6.7.7.10-6ubuntu3.13+esm8
                                   Available with Ubuntu Pro
   libmagick++-dev                 8:6.7.7.10-6ubuntu3.13+esm8
                                   Available with Ubuntu Pro
   libmagick++5                    8:6.7.7.10-6ubuntu3.13+esm8
                                   Available with Ubuntu Pro
   libmagickcore-dev               8:6.7.7.10-6ubuntu3.13+esm8
                                   Available with Ubuntu Pro
   libmagickcore5                  8:6.7.7.10-6ubuntu3.13+esm8
                                   Available with Ubuntu Pro
   libmagickcore5-extra            8:6.7.7.10-6ubuntu3.13+esm8
                                   Available with Ubuntu Pro
   libmagickwand-dev               8:6.7.7.10-6ubuntu3.13+esm8
                                   Available with Ubuntu Pro
   libmagickwand5                  8:6.7.7.10-6ubuntu3.13+esm8
                                   Available with Ubuntu Pro
   perlmagick                      8:6.7.7.10-6ubuntu3.13+esm8
                                   Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6980-1

  CVE-2017-12805, CVE-2017-12806, CVE-2017-13144, CVE-2018-16412,

  CVE-2018-16413, CVE-2018-17966, CVE-2018-18016, CVE-2018-18024,

  CVE-2018-18025, CVE-2018-20467

Severity
important
Lowest
Low
Medium
High
Critical

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here