MDVSA-2012:077
- Nom du paquet
- imagemagick
- Date
- 2012-05-17
- Advisory ID
- MDVSA-2012:077
- Affected versions
- MES5 i586 , MES5 x86_64 , 2010.1 i586 , 2010.1 x86_64
Problem description
Multiple vulnerabilities has been found and corrected in imagemagick:
Untrusted search path vulnerability in configure.c in ImageMagick
before 6.6.5-5, when MAGICKCORE_INSTALLED_SUPPORT is defined, allows
local users to gain privileges via a Trojan horse configuration file
in the current working directory (CVE-2010-4167).
A flaw was found in the way ImageMagick processed images with malformed
Exchangeable image file format (Exif) metadata. An attacker could
create a specially-crafted image file that, when opened by a victim,
would cause ImageMagick to crash or, potentially, execute arbitrary
code (CVE-2012-0247).
A denial of service flaw was found in the way ImageMagick processed
images with malformed Exif metadata. An attacker could create a
specially-crafted image file that, when opened by a victim, could
cause ImageMagick to enter an infinite loop (CVE-2012-0248).
The original fix for CVE-2012-0247 failed to check for the possibility
of an integer overflow when computing the sum of number_bytes and
offset. This resulted in a wrap around into a value smaller than
length, making original CVE-2012-0247 introduced length check still
to be possible to bypass, leading to memory corruption (CVE-2012-1185).
An integer overflow flaw was found in the way ImageMagick processed
certain Exif tags with a large components count. An attacker
could create a specially-crafted image file that, when opened by a
victim, could cause ImageMagick to access invalid memory and crash
(CVE-2012-0259).
A denial of service flaw was found in the way ImageMagick decoded
certain JPEG images. A remote attacker could provide a JPEG image with
specially-crafted sequences of RST0 up to RST7 restart markers (used
to indicate the input stream to be corrupted), which once processed
by ImageMagick, would cause it to consume excessive amounts of memory
and CPU time (CVE-2012-0260).
An out-of-bounds buffer read flaw was found in the way ImageMagick
processed certain TIFF image files. A remote attacker could provide
a TIFF image with a specially-crafted Exif IFD value (the set of tags
for recording Exif-specific attribute information), which once opened
by ImageMagick, would cause it to crash (CVE-2012-1798).
The updated packages have been patched to correct these issues.
Updated packages
MES5 i586
74c481999cfa56013ef04ffba6fc5945 mes5/i586/imagemagick-6.4.2.10-5.3mdvmes5.2.i586.rpm 2b591de902a76d961e483ad447e299b9 mes5/i586/imagemagick-desktop-6.4.2.10-5.3mdvmes5.2.i586.rpm b3353d5b6ac13de56b299dbd1dc1f1d7 mes5/i586/imagemagick-doc-6.4.2.10-5.3mdvmes5.2.i586.rpm a5be187b2d15e57068717be451dbeedd mes5/i586/libmagick1-6.4.2.10-5.3mdvmes5.2.i586.rpm fd04200438ae525dbd594ef8adf74150 mes5/i586/libmagick-devel-6.4.2.10-5.3mdvmes5.2.i586.rpm 12bc440241c35517d681c316e426a55d mes5/i586/perl-Image-Magick-6.4.2.10-5.3mdvmes5.2.i586.rpm 25c05027ec8e9122a9fe18b14d949ebe mes5/SRPMS/imagemagick-6.4.2.10-5.3mdvmes5.2.src.rpm
MES5 x86_64
81b69f7bb9d3e4237a426cae23e21970 mes5/x86_64/imagemagick-6.4.2.10-5.3mdvmes5.2.x86_64.rpm a97f42e2875a0ebc3bc487c657eda457 mes5/x86_64/imagemagick-desktop-6.4.2.10-5.3mdvmes5.2.x86_64.rpm 92d5364d9e74c865fdfb91643247f8c9 mes5/x86_64/imagemagick-doc-6.4.2.10-5.3mdvmes5.2.x86_64.rpm b100d380eb002a3244e1ee661b1633f5 mes5/x86_64/lib64magick1-6.4.2.10-5.3mdvmes5.2.x86_64.rpm d3b569df24eeae5ad3d0c7119e91df8a mes5/x86_64/lib64magick-devel-6.4.2.10-5.3mdvmes5.2.x86_64.rpm 2f3012e2b94ae58b6bdcf513afbda0ae mes5/x86_64/perl-Image-Magick-6.4.2.10-5.3mdvmes5.2.x86_64.rpm 25c05027ec8e9122a9fe18b14d949ebe mes5/SRPMS/imagemagick-6.4.2.10-5.3mdvmes5.2.src.rpm
2010.1 i586
4ff09ac510c672499ee00a416edfc2db 2010.1/i586/imagemagick-6.6.1.5-2.1mdv2010.2.i586.rpm 7373862037711c4b07776f34ff3f4be0 2010.1/i586/imagemagick-desktop-6.6.1.5-2.1mdv2010.2.i586.rpm 8b6a91e231b75db0c0c621649f88290f 2010.1/i586/imagemagick-doc-6.6.1.5-2.1mdv2010.2.i586.rpm f0b6618f6538194cf7052214d68e2871 2010.1/i586/libmagick3-6.6.1.5-2.1mdv2010.2.i586.rpm a520984667c9e98de7652fe597cd193d 2010.1/i586/libmagick-devel-6.6.1.5-2.1mdv2010.2.i586.rpm 7c21957250e196d6a539edfff75ef105 2010.1/i586/perl-Image-Magick-6.6.1.5-2.1mdv2010.2.i586.rpm 56aa3fca43507cbdb5fe248c9314d860 2010.1/SRPMS/imagemagick-6.6.1.5-2.1mdv2010.2.src.rpm
2010.1 x86_64
2409ce33960122226551d2becad53fca 2010.1/x86_64/imagemagick-6.6.1.5-2.1mdv2010.2.x86_64.rpm 93c7a6840fdc4886239e00b6d4e83098 2010.1/x86_64/imagemagick-desktop-6.6.1.5-2.1mdv2010.2.x86_64.rpm 32896b93d2bd840d8656a04876236a51 2010.1/x86_64/imagemagick-doc-6.6.1.5-2.1mdv2010.2.x86_64.rpm e6f4557debbd9cfc3e44d81be6536075 2010.1/x86_64/lib64magick3-6.6.1.5-2.1mdv2010.2.x86_64.rpm 4386810c4640ea9e3561d196f0d00ff2 2010.1/x86_64/lib64magick-devel-6.6.1.5-2.1mdv2010.2.x86_64.rpm 6cde8d3590fc4a3f1e6cf74d8c42c7ed 2010.1/x86_64/perl-Image-Magick-6.6.1.5-2.1mdv2010.2.x86_64.rpm 56aa3fca43507cbdb5fe248c9314d860 2010.1/SRPMS/imagemagick-6.6.1.5-2.1mdv2010.2.src.rpm
References
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1798
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0260
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0259
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1185
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0248
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0247
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4167
