Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Ubuntu 14.04 LTS: USN-7164-1 critical: ImageMagick denial of service

ubuntu
Calendar Grey December 17, 2024
Dist Ubuntu Esm H88
Debian Security Advisory DSA-5167-1 announces a vulnerability in OpenSSL originating from improper handling of crafted data, resulting in potential data leaks.
ImageMagick could be made to crash if it received specially crafted input.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: ImageMagick could be made to crash if it received specially crafted input. Software Description: - imagemagick: Image manipulation programs and library Details: It was discovered that ImageMagick incorrectly handled certain malformed files. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly exploit this to cause a denial of service.

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS   imagemagick                     8:6.7.7.10-6ubuntu3.13+esm12                                   Available with Ubuntu Pro   imagemagick-common              8:6.7.7.10-6ubuntu3.13+esm12                                   Available with Ubuntu Pro   libmagick++-dev                 8:6.7.7.10-6ubuntu3.13+esm12                                   Available with Ubuntu Pro   libmagick++5                    8:6.7.7.10-6ubuntu3.13+esm12                                   Available with Ubuntu Pro   libmagickcore-dev               8:6.7.7.10-6ubuntu3.13+esm12                                   Available with Ubuntu Pro   libmagickcore5                  8:6.7.7.10-6ubuntu3.13+esm12                                   Available with Ubuntu Pro   libmagickcore5-extra            8:6.7.7.10-6ubuntu3.13+esm12                                   Available with Ubuntu Pro   libmagickwand-dev               8:6.7.7.10-6ubuntu3.13+esm12                                   Available with Ubuntu Pro   libmagickwand5                  8:6.7.7.10-6ubuntu3.13+esm12                                   Available with Ubuntu Pro   perlmagick                      8:6.7.7.10-6ubuntu3.13+esm12                                   Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7164-1

  CVE-2021-20176, CVE-2021-20241, CVE-2021-20243

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7164-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here