[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2012:077 -- Mandriva imagemagick

ID: oval:org.secpod.oval:def:302869Date: (C)2012-12-20   (M)2023-11-10
Class: PATCHFamily: unix




Multiple vulnerabilities has been found and corrected in imagemagick: Untrusted search path vulnerability in configure.c in ImageMagick before 6.6.5-5, when MAGICKCORE_INSTALLED_SUPPORT is defined, allows local users to gain privileges via a Trojan horse configuration file in the current working directory . A flaw was found in the way ImageMagick processed images with malformed Exchangeable image file format metadata. An attacker could create a specially-crafted image file that, when opened by a victim, would cause ImageMagick to crash or, potentially, execute arbitrary code . A denial of service flaw was found in the way ImageMagick processed images with malformed Exif metadata. An attacker could create a specially-crafted image file that, when opened by a victim, could cause ImageMagick to enter an infinite loop . The original fix for CVE-2012-0247 failed to check for the possibility of an integer overflow when computing the sum of number_bytes and offset. This resulted in a wrap around into a value smaller than length, making original CVE-2012-0247 introduced length check still to be possible to bypass, leading to memory corruption . An integer overflow flaw was found in the way ImageMagick processed certain Exif tags with a large components count. An attacker could create a specially-crafted image file that, when opened by a victim, could cause ImageMagick to access invalid memory and crash . A denial of service flaw was found in the way ImageMagick decoded certain JPEG images. A remote attacker could provide a JPEG image with specially-crafted sequences of RST0 up to RST7 restart markers , which once processed by ImageMagick, would cause it to consume excessive amounts of memory and CPU time . An out-of-bounds buffer read flaw was found in the way ImageMagick processed certain TIFF image files. A remote attacker could provide a TIFF image with a specially-crafted Exif IFD value , which once opened by ImageMagick, would cause it to crash . The updated packages have been patched to correct these issues.

Platform:
Mandriva Linux 2010.1
Product:
imagemagick
Reference:
MDVSA-2012:077
CVE-2012-1798
CVE-2012-0260
CVE-2012-0259
CVE-2012-1185
CVE-2012-0248
CVE-2012-0247
CVE-2010-4167
CVE    7
CVE-2012-0260
CVE-2012-0248
CVE-2012-0259
CVE-2012-0247
...
CPE    1
cpe:/o:mandriva:linux:2010.1

© SecPod Technologies