LWN.net Logo

rPath alert rPSA-2006-0159-1 (ImageMagick)

From:  "Justin M. Forbes" <jmforbes@rpath.com>
To:  security-announce@lists.rpath.com, update-announce@lists.rpath.com
Subject:  rPSA-2006-0159-1 ImageMagick
Date:  Tue, 29 Aug 2006 11:14:27 -0400
Cc:  full-disclosure@lists.grok.org.uk, bugtraq@securityfocus.com, lwn@lwn.net

rPath Security Advisory: 2006-0159-1 Published: 2006-08-29 Products: rPath Linux 1 Rating: Major Exposure Level Classification: Indirect User Deterministic Unauthorized Access Updated Versions: ImageMagick=/conary.rpath.com@rpl:devel//1/6.2.3.3-3.2-1 References: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-200... http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-200... http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-200... https://issues.rpath.com/browse/RPL-605 Description: In previous versions of the ImageMagick package, the sun bitmap, GIMP xcf, and sgi image decoders contain vulnerabilities that enable attackers to cause arbitrary code execution when using ImageMagick programs or libraries to access malformed images of those types.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds