Oval Definition:oval:com.redhat.rhsa:def:20050070
Revision Date:2005-03-23Version:502
Title:RHSA-2005:070: ImageMagick security update (Moderate)
Description:ImageMagick is an image display and manipulation tool for the X Window System.

Andrei Nigmatulin discovered a heap based buffer overflow flaw in the ImageMagick image handler. An attacker could create a carefully crafted Photoshop Document (PSD) image in such a way that it would cause ImageMagick to execute arbitrary code when processing the image. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0005 to this issue.

A format string bug was found in the way ImageMagick handles filenames. An attacker could execute arbitrary code on a victim's machine if they were able to trick the victim into opening a file with a specially crafted name. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0397 to this issue.

A bug was found in the way ImageMagick handles TIFF tags. It is possible that a TIFF image file with an invalid tag could cause ImageMagick to crash. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0759 to this issue.

A bug was found in ImageMagick's TIFF decoder. It is possible that a specially crafted TIFF image file could cause ImageMagick to crash. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0760 to this issue.

A bug was found in the way ImageMagick parses PSD files. It is possible that a specially crafted PSD file could cause ImageMagick to crash. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0761 to this issue.

A heap overflow bug was found in ImageMagick's SGI parser. It is possible that an attacker could execute arbitrary code by tricking a user into opening a specially crafted SGI image file. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0762 to this issue.

Users of ImageMagick should upgrade to these updated packages, which contain backported patches, and are not vulnerable to these issues.
Family:unixClass:patch
Status:Reference(s):CVE-2005-0005
CVE-2005-0397
CVE-2005-0759
CVE-2005-0760
CVE-2005-0761
CVE-2005-0762
RHSA-2005:070-01
Platform(s):Red Hat Enterprise Linux 3
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux 3 is installed
  • AND Package Information
  • ImageMagick-c++-devel is earlier than 0:5.5.6-13
  • AND ImageMagick-c++-devel is signed with Red Hat master key
  • OR
  • ImageMagick-devel is earlier than 0:5.5.6-13
  • AND ImageMagick-devel is signed with Red Hat master key
  • OR
  • ImageMagick-perl is earlier than 0:5.5.6-13
  • AND ImageMagick-perl is signed with Red Hat master key
  • OR
  • ImageMagick is earlier than 0:5.5.6-13
  • AND ImageMagick is signed with Red Hat master key
  • OR
  • ImageMagick-c++ is earlier than 0:5.5.6-13
  • AND ImageMagick-c++ is signed with Red Hat master key
  • BACK