Bryan Gonzalez discovered that the PNG support in Imagemagick could be tricked into embedding the content of an arbitrary file when converting an image file. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5347-1
New imagemagick packages are available for Slackware 9.1, 10.0, and -current to fix security issues with PNG images. More details about the issues with PNG may be found in the Common Vulnerabilities and Exposures (CVE) database: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] imagemagick (SSA:2004-223-02) New imagemagick packages are available for Slackware 9.1, 10.0, and -current to fix security issues with PNG images. More details about the issues with PNG may be found in the Common Vulnerabilities and Exposures (CVE) database: https://www.cve.org/CVERecord?id=CAN-2004-0597 https://www.cve.org/CVERecord?id=CAN-2004-0598 https://www.cve.org/CVERecord?id=CAN-2004-0599 Here are the details from the Slackware 10.0 ChangeLog: +--------------------------+ Sat Aug 7 17:17:20 AKDT 2004 patches/packages/imagemagick-6.0.4_3-i486-1.tgz: Upgraded to ImageMagick-6.0.4-3. Fixes PNG security issues. (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Updated package for Slackware 9.1: ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/imagemagick-5.5.7_25-i486-1.tgz Updated package for Slackware 10.0: ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/imagemagick-6.0.4_3-i486-1.tgz Updated package for Slackware -current: MD5 signatures: +-------------+ Slackware 9.1 package: 52903d349dcbaf3be88d19c8aa05dbbf imagemagick-5.5.7_25-i486-1.tgz Slackware 10.0 package: ad5531a33331029dcc7013b72f8ec792 imagemagick-6.0.4_3-i486-1.tgz Slackware -current package: ad5531a33331029dcc7013b72f8ec792 imagemagick-6.0.4_3-i486-1.tgz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg imagemagick-6.0.4_3-i486-1.tgz +-----+ . Latest ImageMagick updates for Slackware address vulnerabilities in PNG files. Upgrade immediately to enhance your system's security.. imagemagick, slackware security, png vulnerabilities, software update, security patch.. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.