USN-5158-1
Dashboard / Vulnerabilities / USN-5158-1
USN-5158-1
Summary: imagemagick vulnerabilities
Details: It was discovered that ImageMagick incorrectly handled certain values when processing visual effects based image files. By tricking a user into opening a specially crafted image file, an attacker could crash the application causing a denial of service. (CVE-2021-20244) It was discovered that ImageMagick incorrectly handled certain values when performing resampling operations. By tricking a user into opening a specially crafted image file, an attacker could crash the application causing a denial of service. (CVE-2021-20246) It was discovered that ImageMagick incorrectly handled certain values when processing visual effects based image files. By tricking a user into opening a specially crafted image file, an attacker could crash the application causing a denial of service (CVE-2021-20309) It was discovered that ImageMagick incorrectly handled certain values when processing thumbnail image data. By tricking a user into opening a specially crafted image file, an attacker could crash the application causing a denial of service. (CVE-2021-20312) It was discovered that ImageMagick incorrectly handled memory cleanup when performing certain cryptographic operations. Under certain conditions sensitive cryptographic information could be disclosed. (CVE-2021-20313)
References: https://ubuntu.com/security/notices/USN-5158-1, https://ubuntu.com/security/CVE-2021-20244, https://ubuntu.com/security/CVE-2021-20246, https://ubuntu.com/security/CVE-2021-20309, https://ubuntu.com/security/CVE-2021-20312, https://ubuntu.com/security/CVE-2021-20313
Affected packages
Package
Name: imagemagick
Purl: pkg:deb/ubuntu/imagemagick?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
