drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in ImageMagick
| Name: |
Mehrere Probleme in ImageMagick |
|
| ID: |
USN-1435-1 |
|
| Distribution: |
Ubuntu |
|
| Plattformen: |
Ubuntu 10.04 LTS, Ubuntu 11.04, Ubuntu 11.10, Ubuntu 12.04 LTS |
|
| Datum: |
Di, 1. Mai 2012, 21:16 |
|
| Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0247
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0248
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0259
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1185
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1186
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1610
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1798 |
|
Originalnachricht |
--===============3036469682169464083== Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="=-nfrIGYdEYdi7MOHTCn9x"
--=-nfrIGYdEYdi7MOHTCn9x Content-Type: text/plain; charset="UTF-8 Content-Transfer-Encoding: quoted-printable
========================================================================== Ubuntu Security Notice USN-1435-1 May 01, 2012
imagemagick vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS - Ubuntu 11.10 - Ubuntu 11.04 - Ubuntu 10.04 LTS
Summary:
ImageMagick could be made to crash or run programs as your login if it opened a specially crafted file.
Software Description: - imagemagick: Image manipulation programs and library
Details:
Joonas Kuorilehto and Aleksis Kauppinen discovered that ImageMagick incorrectly handled certain ResolutionUnit tags. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privileges of the user invoking the program. (CVE-2012-0247, CVE-2012-1185)
Joonas Kuorilehto and Aleksis Kauppinen discovered that ImageMagick incorrectly handled certain IFD structures. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service. (CVE-2012-0248, CVE-2012-1186)
Aleksis Kauppinen, Joonas Kuorilehto and Tuomas Parttimaa discovered that ImageMagick incorrectly handled certain JPEG EXIF tags. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service. (CVE-2012-0259)
It was discovered that ImageMagick incorrectly handled certain JPEG EXIF tags. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privileges of the user invoking the program. (CVE-2012-1610)
Aleksis Kauppinen, Joonas Kuorilehto and Tuomas Parttimaa discovered that ImageMagick incorrectly handled certain TIFF EXIF tags. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privileges of the user invoking the program. (CVE-2012-1798)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 12.04 LTS: imagemagick 8:6.6.9.7-5ubuntu3.1 libmagick++4 8:6.6.9.7-5ubuntu3.1
Ubuntu 11.10: imagemagick 8:6.6.0.4-3ubuntu1.1 libmagick++3 8:6.6.0.4-3ubuntu1.1
Ubuntu 11.04: imagemagick 7:6.6.2.6-1ubuntu4.1 libmagick++3 7:6.6.2.6-1ubuntu4.1
Ubuntu 10.04 LTS: imagemagick 7:6.5.7.8-1ubuntu1.2 libmagick++2 7:6.5.7.8-1ubuntu1.2
In general, a standard system update will make all the necessary changes.
References: http://www.ubuntu.com/usn/usn-1435-1 CVE-2012-0247, CVE-2012-0248, CVE-2012-0259, CVE-2012-1185, CVE-2012-1186, CVE-2012-1610, CVE-2012-1798
Package Information: https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.1 https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.0.4-3ubuntu1.1 https://launchpad.net/ubuntu/+source/imagemagick/7:6.6.2.6-1ubuntu4.1 https://launchpad.net/ubuntu/+source/imagemagick/7:6.5.7.8-1ubuntu1.2
--×frIGYdEYdi7MOHTCn9x Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part Content-Transfer-Encoding: 7bit
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux)
iQIcBAABCgAGBQJPoAI1AAoJEGVp2FWnRL6TZggQALNswmEy4akKM1E5sGXeueo8 oj3pJqFSsPfpQpLtHH+2X+c6ds4BRPILf3nUAXVQsdaa/WLBY92dWObbREhXY1OO f3XrLZ4ejfpu9aH4/hE13Vt0VIHK0yFMRtvihhQzQJT/tfktGlW89xtqdI83HBCl SacYZ09Sj0gVDUOFUhGFN9DclQw3ESxJRVWXfLXtCUg0iV5LtwYQzNpAhyEKyYRA 39oDFkRUO8hTHUgIFuzmux52Y/2YknXPUXQ0wFV3KKbTcowfJWcFU2pYvOrKG3Cs wPM0vKu7hDT+6OWLfbSiXczM18gkEhbvcKfI4lK/1Tv4UOTgYNBHrmybHQMW0o7o LTy+/tQ8zjFJkx4Pm1aTjCYiB9EO7rc6QKd2UDZwe5Lu6+d5cfbjCdmg72GjDgfM nPFS7IJkaqftnmdQDKXZPDBAEuvLd/WXdEkCxgCzYDiFKTMF2SJ3PbxtO6WAgC26 Gk6fAG5BfOMfi9kacaWfvjxdf0JOBnpwQYHzsRHoVwqAPLGrJzKPuKHv+HVn+gmm l8ChCc+dnv7SjfMtNZ0WJ9weKw07E/AwmKv+uqhokKdK8+cxAoSuGZ6f3sLLLE07 YI0rP1TmqTkm3xXqQgjlisNJCGOWfWZMec3EX66eGj/bBmEWXtLI6y7UFb8vlKLN qM6Hd3882HJVEpRX+I1Q =oT5M -----END PGP SIGNATURE-----
--=-nfrIGYdEYdi7MOHTCn9x--
--===============3036469682169464083== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
--===============3036469682169464083==--
|
|
|
|