Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Ubuntu 14.04 LTS: USN-6985-1 Moderate: ImageMagick DoS Exploits

ubuntu
Calendar Grey September 4, 2024
Scroller Ubuntu
Solutions for security issues in ImageMagick as per Ubuntu USN-6985-1; includes user patching guidelines.
Several security issues were fixed in ImageMagick.

Summary

Several security issues were fixed in ImageMagick.

Software Description:

- imagemagick: Image manipulation programs and library

Details:

It was discovered that ImageMagick incorrectly handled certain malformed

image files. If a user or automated system using ImageMagick were tricked

into opening a specially crafted image, an attacker could exploit this to

cause a denial of service or execute code with the privileges of the user

invoking the program.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS
   imagemagick                     8:6.7.7.10-6ubuntu3.13+esm9
                                   Available with Ubuntu Pro
   imagemagick-common              8:6.7.7.10-6ubuntu3.13+esm9
                                   Available with Ubuntu Pro
   libmagick++-dev                 8:6.7.7.10-6ubuntu3.13+esm9
                                   Available with Ubuntu Pro
   libmagick++5                    8:6.7.7.10-6ubuntu3.13+esm9
                                   Available with Ubuntu Pro
   libmagickcore-dev               8:6.7.7.10-6ubuntu3.13+esm9
                                   Available with Ubuntu Pro
   libmagickcore5                  8:6.7.7.10-6ubuntu3.13+esm9
                                   Available with Ubuntu Pro
   libmagickcore5-extra            8:6.7.7.10-6ubuntu3.13+esm9
                                   Available with Ubuntu Pro
   libmagickwand-dev               8:6.7.7.10-6ubuntu3.13+esm9
                                   Available with Ubuntu Pro
   libmagickwand5                  8:6.7.7.10-6ubuntu3.13+esm9
                                   Available with Ubuntu Pro
   perlmagick                      8:6.7.7.10-6ubuntu3.13+esm9
                                   Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6985-1

  CVE-2019-10131, CVE-2019-10650, CVE-2019-11470, CVE-2019-11472,

  CVE-2019-11597, CVE-2019-11598, CVE-2019-12974, CVE-2019-12975,

  CVE-2019-12976, CVE-2019-12978, CVE-2019-12979

Ubuntu Security Notice USN-6985-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.