Synopsis: Moderate: ImageMagick security and bug fix update Issue date: 2010-08-25 CVE Names: CVE-2009-1882 An integer overflow flaw, leading to a heap-based buffer overflow, was found in the ImageMagick routine responsible for creating X11 images. An attacker could create a specially-crafted image file that, when opened by a victim, would cause ImageMagick to crash or, potentially, execute arbitrary code. (CVE-2009-1882) This update also fixes the following bug: * previously, portions of certain RGB images on the right side were not rendered and left black when converting or displaying them. With this update, RGB images display correctly. (BZ#625058) All running instances of ImageMagick must be restarted for this update to take effect. SL 5.x SRPMS: ImageMagick-6.2.8.0-4.el5_5.2.src.rpm i386: ImageMagick-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-c++-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-c++-devel-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-devel-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-perl-6.2.8.0-4.el5_5.2.i386.rpm x86_64: ImageMagick-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-6.2.8.0-4.el5_5.2.x86_64.rpm ImageMagick-c++-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-c++-6.2.8.0-4.el5_5.2.x86_64.rpm ImageMagick-c++-devel-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-c++-devel-6.2.8.0-4.el5_5.2.x86_64.rpm ImageMagick-devel-6.2.8.0-4.el5_5.2.i386.rpm ImageMagick-devel-6.2.8.0-4.el5_5.2.x86_64.rpm ImageMagick-perl-6.2.8.0-4.el5_5.2.x86_64.rpm -Connie Sieh -Troy Dawson