Subject: | |
From: | |
Reply To: | |
Date: | Wed, 25 Aug 2010 15:21:28 -0500 |
Content-Type: | text/plain |
Parts/Attachments: |
|
|
Synopsis: Moderate: ImageMagick security and bug fix update
Issue date: 2010-08-25
CVE Names: CVE-2009-1882
An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the ImageMagick routine responsible for creating X11 images. An
attacker could create a specially-crafted image file that, when opened
by a victim, would cause ImageMagick to crash or, potentially, execute
arbitrary code. (CVE-2009-1882)
This update also fixes the following bug:
* previously, portions of certain RGB images on the right side were not
rendered and left black when converting or displaying them. With this
update, RGB images display correctly. (BZ#625058)
All running instances of ImageMagick must be restarted for this update
to take effect.
SL 5.x
SRPMS:
ImageMagick-6.2.8.0-4.el5_5.2.src.rpm
i386:
ImageMagick-6.2.8.0-4.el5_5.2.i386.rpm
ImageMagick-c++-6.2.8.0-4.el5_5.2.i386.rpm
ImageMagick-c++-devel-6.2.8.0-4.el5_5.2.i386.rpm
ImageMagick-devel-6.2.8.0-4.el5_5.2.i386.rpm
ImageMagick-perl-6.2.8.0-4.el5_5.2.i386.rpm
x86_64:
ImageMagick-6.2.8.0-4.el5_5.2.i386.rpm
ImageMagick-6.2.8.0-4.el5_5.2.x86_64.rpm
ImageMagick-c++-6.2.8.0-4.el5_5.2.i386.rpm
ImageMagick-c++-6.2.8.0-4.el5_5.2.x86_64.rpm
ImageMagick-c++-devel-6.2.8.0-4.el5_5.2.i386.rpm
ImageMagick-c++-devel-6.2.8.0-4.el5_5.2.x86_64.rpm
ImageMagick-devel-6.2.8.0-4.el5_5.2.i386.rpm
ImageMagick-devel-6.2.8.0-4.el5_5.2.x86_64.rpm
ImageMagick-perl-6.2.8.0-4.el5_5.2.x86_64.rpm
-Connie Sieh
-Troy Dawson
|
|
|