• [SECURITY] [DSA 2750-1] imagemagick security update

    From Florian Weimer@1:229/2 to All on Tue Sep 3 22:20:02 2013
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-2750-1 [email protected] http://www.debian.org/security/ Florian Weimer September 03, 2013 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : imagemagick
    Vulnerability : buffer overflow
    Problem type : local
    Debian-specific: no
    CVE ID : CVE-2013-4298
    Debian Bug : 721273

    Anton Kortunov reported a heap corruption in ImageMagick, a program
    collection and library for converting and manipulating image files.
    Crafted GIF files could cause ImageMagick to crash, potentially
    leading to arbitrary code execution.

    The oldstable distribution (squeeze) is not affected by this problem.

    For the stable distribution (wheezy), this problem has been fixed in
    version 8:6.7.7.10-5+deb7u2.

    For the unstable distribution (sid), this problem has been fixed in
    version 8:6.7.7.10-6.

    We recommend that you upgrade your imagemagick packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: http://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.10 (GNU/Linux)

    iQEcBAEBAgAGBQJSJkb5AAoJEL97/wQC1SS+7CAIAI+AsoTtBpeeDOeXkwyfJXlN ORBb8X3ZHWZRO/TLIu/GiZVRfiAoiRyON7HpdOYhLY3ELHWKdWn1RzujVfSxJ8tL Xj6zOWTOe+lVTaFlDCbmayKqO+ykDm0ZCYzANN2PiV7m7TbuYSTIlzHojjUe+pyu A9W1Q7MUu4UfeSvEfATlLBv80i54JvG8CmnbsGLc9L63HTBZ4tSDEaxTn+NRd3kE hS1SAjthUkcNWKRN4G4VK3FtGafq4n/o4mGpucgx+akSMXSYkIIpYqDyUJdCklH0 hQjwcXvkSmV05ij6WL6fmL+PFS3e6T426B0xL0MhinqY2rf4x1luwSChMd/aN1I=
    =QFU6
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)