Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Ubuntu 7068-1 moderate: ImageMagick DoS and memory leak issues

ubuntu
Calendar Grey October 15, 2024
Scroller Ubuntu
To bolster security in Ubuntu's ImageMagick, regularly update and patch software, limit image formats, and implement user permissions to prevent exploitation
Several security issues were fixed in ImageMagick.

Summary

Several security issues were fixed in ImageMagick.

Software Description:

- imagemagick: Image manipulation programs and library

Details:

It was discovered that ImageMagick incorrectly handled certain

malformed image files. If a user or automated system using ImageMagick

were tricked into processing a specially crafted file, an attacker could

exploit this to cause a denial of service or affect the reliability of the

system. The vulnerabilities included memory leaks, buffer overflows, and

improper handling of pixel data.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS
   imagemagick-6.q16               8:6.8.9.9-7ubuntu5.16+esm11
                                   Available with Ubuntu Pro
   libimage-magick-perl            8:6.8.9.9-7ubuntu5.16+esm11
                                   Available with Ubuntu Pro
   libimage-magick-q16-perl        8:6.8.9.9-7ubuntu5.16+esm11
                                   Available with Ubuntu Pro
   libmagick++-6.q16-5v5           8:6.8.9.9-7ubuntu5.16+esm11
                                   Available with Ubuntu Pro
   libmagickcore-6-headers         8:6.8.9.9-7ubuntu5.16+esm11
                                   Available with Ubuntu Pro
   libmagickcore-6.q16-2           8:6.8.9.9-7ubuntu5.16+esm11
                                   Available with Ubuntu Pro
   libmagickcore-6.q16-2-extra     8:6.8.9.9-7ubuntu5.16+esm11
                                   Available with Ubuntu Pro
   libmagickcore-6.q16-dev         8:6.8.9.9-7ubuntu5.16+esm11
                                   Available with Ubuntu Pro
   libmagickwand-6.q16-2           8:6.8.9.9-7ubuntu5.16+esm11
                                   Available with Ubuntu Pro

Ubuntu 14.04 LTS
   imagemagick                     8:6.7.7.10-6ubuntu3.13+esm11
                                   Available with Ubuntu Pro
   libmagick++-dev                 8:6.7.7.10-6ubuntu3.13+esm11
                                   Available with Ubuntu Pro
   libmagick++5                    8:6.7.7.10-6ubuntu3.13+esm11
                                   Available with Ubuntu Pro
   libmagickcore-dev               8:6.7.7.10-6ubuntu3.13+esm11
                                   Available with Ubuntu Pro
   libmagickcore5                  8:6.7.7.10-6ubuntu3.13+esm11
                                   Available with Ubuntu Pro
   libmagickcore5-extra            8:6.7.7.10-6ubuntu3.13+esm11
                                   Available with Ubuntu Pro
   libmagickwand-dev               8:6.7.7.10-6ubuntu3.13+esm11
                                   Available with Ubuntu Pro
   libmagickwand5                  8:6.7.7.10-6ubuntu3.13+esm11
                                   Available with Ubuntu Pro
   perlmagick                      8:6.7.7.10-6ubuntu3.13+esm11
                                   Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7068-1

  CVE-2019-7397, CVE-2019-7398, CVE-2019-9956, CVE-2020-19667,

  CVE-2020-25664, CVE-2020-25665, CVE-2020-25666, CVE-2020-25674,

  CVE-2020-25676, CVE-2020-27560, CVE-2020-27750, CVE-2020-27753,

  CVE-2020-27754, CVE-2020-27755, CVE-2020-27758, CVE-2020-27759,

  CVE-2020-27760, CVE-2020-27761, CVE-2020-27762, CVE-2020-27763,

  CVE-2020-27764, CVE-2020-27765, CVE-2020-27766, CVE-2020-27767,

  CVE-2020-27768, CVE-2020-27769, CVE-2020-27770, CVE-2020-27771,

  CVE-2020-27772, CVE-2020-27773, CVE-2020-27774, CVE-2020-27775,

  CVE-2020-27776

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.