GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Sat May 21, 2005 3:52 pm Post subject: [ GLSA 200505-16 ] ImageMagick, GraphicsMagick: Denial of Se |
|
|
Gentoo Linux Security Advisory
Title: ImageMagick, GraphicsMagick: Denial of Service vulnerability (GLSA 200505-16)
Severity: normal
Exploitable: remote
Date: May 21, 2005
Updated: May 22, 2006
Bug(s): #90423, #90595
ID: 200505-16
Synopsis
ImageMagick and GraphicsMagick utilities can be abused to perform a Denial of Service attack.
Background
Both ImageMagick and GraphicsMagick are collection of tools to read, write and manipulate images in many formats.
Affected Packages
Package: media-gfx/imagemagick
Vulnerable: < 6.2.2.3
Unaffected: >= 6.2.2.3
Architectures: All supported architectures
Package: media-gfx/graphicsmagick
Vulnerable: < 1.1.6-r1
Unaffected: >= 1.1.6-r1
Architectures: All supported architectures
Description
Tavis Ormandy of the Gentoo Linux Security Audit Team discovered a Denial of Service vulnerability in the XWD decoder of ImageMagick and GraphicsMagick when setting a color mask to zero.
Impact
A remote attacker could submit a specially crafted image to a user or an automated system making use of an affected utility, resulting in a Denial of Service by consumption of CPU time.
Workaround
There is no known workaround at this time.
Resolution
All ImageMagick users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=media-gfx/imagemagick-6.2.2.3" | All GraphicsMagick users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=media-gfx/graphicsmagick-1.1.6-r1" |
References
CVE-2005-1739
Last edited by GLSA on Mon May 22, 2006 4:19 am; edited 2 times in total |
|