USN-2990-1
Dashboard / Vulnerabilities / USN-2990-1
USN-2990-1
Summary: imagemagick vulnerabilities
Details: Nikolay Ermishkin and Stewie discovered that ImageMagick incorrectly sanitized untrusted input. A remote attacker could use these issues to execute arbitrary code. These issues are known as "ImageTragick". This update disables problematic coders via the /etc/ImageMagick-6/policy.xml configuration file. In certain environments the coders may need to be manually re-enabled after making sure that ImageMagick does not process untrusted input. (CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717, CVE-2016-3718) Bob Friesenhahn discovered that ImageMagick allowed injecting commands via an image file or filename. A remote attacker could use this issue to execute arbitrary code. (CVE-2016-5118)
References: https://ubuntu.com/security/notices/USN-2990-1, https://ubuntu.com/security/CVE-2016-3714, https://ubuntu.com/security/CVE-2016-3715, https://ubuntu.com/security/CVE-2016-3716, https://ubuntu.com/security/CVE-2016-3717, https://ubuntu.com/security/CVE-2016-3718, https://ubuntu.com/security/CVE-2016-5118
Affected packages
Package
Name: imagemagick
Purl: pkg:deb/ubuntu/imagemagick@8:6.7.7.10-6ubuntu3.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
