Gentoo Archives: gentoo-announce

From: Thierry Carrez <koon@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200505-16 ] ImageMagick, GraphicsMagick: Denial of Service vulnerability
Date: Sat, 21 May 2005 15:33:29
Message-Id: 428F54C9.9010008@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200505-16
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: ImageMagick, GraphicsMagick: Denial of Service
9 vulnerability
10 Date: May 21, 2005
11 Bugs: #90423, #90595
12 ID: 200505-16
13
14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
15
16 Synopsis
17 ========
18
19 ImageMagick and GraphicsMagick utilities can be abused to perform a
20 Denial of Service attack.
21
22 Background
23 ==========
24
25 Both ImageMagick and GraphicsMagick are collection of tools to read,
26 write and manipulate images in many formats.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 media-gfx/imagemagick < 6.2.2.3 >= 6.2.2.3
35 2 media-gfx/graphicsmagick < 1.1.6-r1 >= 1.1.6-r1
36 -------------------------------------------------------------------
37 2 affected packages on all of their supported architectures.
38 -------------------------------------------------------------------
39
40 Description
41 ===========
42
43 Tavis Ormandy of the Gentoo Linux Security Audit Team discovered a
44 Denial of Service vulnerability in the XWD decoder of ImageMagick and
45 GraphicsMagick when setting a color mask to zero.
46
47 Impact
48 ======
49
50 A remote attacker could submit a specially crafted image to a user or
51 an automated system making use of an affected utility, resulting in a
52 Denial of Service by consumption of CPU time.
53
54 Workaround
55 ==========
56
57 There is no known workaround at this time.
58
59 Resolution
60 ==========
61
62 All ImageMagick users should upgrade to the latest version:
63
64 # emerge --sync
65 # emerge --ask --oneshot --verbose ">=media-gfx/imagemagick-6.2.2.3"
66
67 All GraphicsMagick users should upgrade to the latest version:
68
69 # emerge --sync
70 # emerge --ask --oneshot --verbose ">=media-gfx/graphicsmagick-1.1.6-r1"
71
72 Availability
73 ============
74
75 This GLSA and any updates to it are available for viewing at
76 the Gentoo Security Website:
77
78 http://security.gentoo.org/glsa/glsa-200505-16.xml
79
80 Concerns?
81 =========
82
83 Security is a primary focus of Gentoo Linux and ensuring the
84 confidentiality and security of our users machines is of utmost
85 importance to us. Any security concerns should be addressed to
86 security@g.o or alternatively, you may file a bug at
87 http://bugs.gentoo.org.
88
89 License
90 =======
91
92 Copyright 2005 Gentoo Foundation, Inc; referenced text
93 belongs to its owner(s).
94
95 The contents of this document are licensed under the
96 Creative Commons - Attribution / Share Alike license.
97
98 http://creativecommons.org/licenses/by-sa/2.0

Attachments

File name MIME type
signature.asc application/pgp-signature