Secunia Logo
Netsikker nu! 2008
 
SUSE update for imagemagick
Secunia Advisory: SA14700
Release Date: 2005-03-24
Popularity: 6,801 views

Critical:
Moderately critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch

OS:SuSE Linux 8.x
SuSE Linux 9.0
SuSE Linux 9.1
SUSE Linux 9.2
SuSE Linux Desktop 1.x
SuSE Linux Enterprise Server 8
SUSE Linux Enterprise Server 9

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2005-0397
CVE-2005-0759
CVE-2005-0760
CVE-2005-0761
CVE-2005-0762


Description:
SUSE has issued an update for imagemagick. This fixes some vulnerabilities, which potentially can be exploited by malicious people to compromise a user's system.

1) A format string error within the handling of filenames can be exploited to execute arbitrary code by via a specially crafted filename containing format specifiers.

For more information:
SA14466

2) An unspecified boundary error within the handling of SGI files can be exploited cause a heap-based buffer overflow and potentially execute arbitrary code via a specially crafted SGI file.

This update also fixes some other errors in the handling of TIFF and PSD images, which can be exploited to crash ImageMagick.

Solution:
Apply updated packages.

-- x86 Platform --

SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/upda...m/i586/ImageMagick-6.0.7-4.6.i586.rpm
e0abc35e5b6e62c411d20ef6e2e9f977
ftp://ftp.suse.com/pub/suse/i386/upda...ageMagick-Magick++-6.0.7-4.6.i586.rpm
03e732ad0f84a86746b9c227fc89b445
ftp://ftp.suse.com/pub/suse/i386/upda.../ImageMagick-devel-6.0.7-4.6.i586.rpm
c284ca68e325b91406ddd7d89d469578
ftp://ftp.suse.com/pub/suse/i386/upda...86/perl-PerlMagick-6.0.7-4.6.i586.rpm
1b266f8322f93bf46889bcede41807b2

SUSE Linux 9.1:
ftp://ftp.suse.com/pub/suse/i386/upda...586/ImageMagick-5.5.7-225.15.i586.rpm
f9b715bc0b7a903d7d9ed05bb185e305
ftp://ftp.suse.com/pub/suse/i386/upda...Magick-Magick++-5.5.7-225.15.i586.rpm
a2f7fc378cfe423636e85d41ce2e84a3
ftp://ftp.suse.com/pub/suse/i386/upda...ageMagick-devel-5.5.7-225.15.i586.rpm
bd64b2c1a6725453e5c76fb8fa6504a9
ftp://ftp.suse.com/pub/suse/i386/upda...perl-PerlMagick-5.5.7-225.15.i586.rpm
b8b09bdc13ad121251b206b0c867250a
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/upda.../src/ImageMagick-5.5.7-225.15.src.rpm
25266f599e107cb3587b78311c3526d7

SUSE Linux 9.0:
ftp://ftp.suse.com/pub/suse/i386/upda...m/i586/ImageMagick-5.5.7-233.i586.rpm
efe3d14315a46951b3c9b67d77ae7e24
ftp://ftp.suse.com/pub/suse/i386/upda...ageMagick-Magick++-5.5.7-233.i586.rpm
d2edc9ca9c44981a804081ceee7995e8
ftp://ftp.suse.com/pub/suse/i386/upda.../ImageMagick-devel-5.5.7-233.i586.rpm
c596c37ffc1037edd206f2ed2b7aba8c
ftp://ftp.suse.com/pub/suse/i386/upda...86/perl-PerlMagick-5.5.7-233.i586.rpm
0cdf7ec0f6a284fd1ecd0f8b4669f106
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/upda...rpm/src/ImageMagick-5.5.7-233.src.rpm
388fc41c453baecab3249d0c5520e509

SUSE Linux 8.2:
ftp://ftp.suse.com/pub/suse/i386/upda...m/i586/ImageMagick-5.5.4-125.i586.rpm
f1fd06f68f5d1340aa48a1249a666b42
ftp://ftp.suse.com/pub/suse/i386/upda...ageMagick-Magick++-5.5.4-125.i586.rpm
476eb03a384a7f3295f0933bfd22037b
ftp://ftp.suse.com/pub/suse/i386/upda.../ImageMagick-devel-5.5.4-125.i586.rpm
1fe5babe00b1a2e3b29b27afdc49a5eb
ftp://ftp.suse.com/pub/suse/i386/upda...86/perl-PerlMagick-5.5.4-125.i586.rpm
7b4954080bed5957fc4dafc139877ffb
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/upda...rpm/src/ImageMagick-5.5.4-125.src.rpm
fb728261f74de1c886b8e89c6ccdc527


-- x86-64 Platform --

SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/upda...6_64/ImageMagick-6.0.7-4.6.x86_64.rpm
2b5031672b87983839255c62a8d2b6c6
ftp://ftp.suse.com/pub/suse/i386/upda...eMagick-Magick++-6.0.7-4.6.x86_64.rpm
65e2f75380c5c09318de2c2d5341dd8f
ftp://ftp.suse.com/pub/suse/i386/upda...mageMagick-devel-6.0.7-4.6.x86_64.rpm
dd81443b6ddd154a7c0f5af0ba107686
ftp://ftp.suse.com/pub/suse/i386/upda.../perl-PerlMagick-6.0.7-4.6.x86_64.rpm
a7900a8703a0fe17ff64ff9dcb9e52f4
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/upda...rpm/src/ImageMagick-6.0.7-4.6.src.rpm
610adb7f10d61555aa46b27e29eebf05

SUSE Linux 9.1:
ftp://ftp.suse.com/pub/suse/x86_64/up...4/ImageMagick-5.5.7-225.15.x86_64.rpm
6ea3b05343ea37f54b0912576e5bc6e7
ftp://ftp.suse.com/pub/suse/x86_64/up...gick-Magick++-5.5.7-225.15.x86_64.rpm
7b9e5c6e6094abc2f11f2817ca513b89
ftp://ftp.suse.com/pub/suse/x86_64/up...eMagick-devel-5.5.7-225.15.x86_64.rpm
c0f61d39f21a1b365f301515230a357b
ftp://ftp.suse.com/pub/suse/x86_64/up...rl-PerlMagick-5.5.7-225.15.x86_64.rpm
c9e54772c1cd1ad6a06bafd926377095
source rpm(s):
ftp://ftp.suse.com/pub/suse/x86_64/up.../src/ImageMagick-5.5.7-225.15.src.rpm
49128ab7a073c5c65883801bafa60a6b

SUSE Linux 9.0:
ftp://ftp.suse.com/pub/suse/x86_64/up...6_64/ImageMagick-5.5.7-233.x86_64.rpm
7b7cbce2c54582984747576efe1d551d
ftp://ftp.suse.com/pub/suse/x86_64/up...eMagick-Magick++-5.5.7-233.x86_64.rpm
108267eb5c839b17b878d63a351c1ee1
ftp://ftp.suse.com/pub/suse/x86_64/up...mageMagick-devel-5.5.7-233.x86_64.rpm
34a4699f690dc4b11c347274abddb6fe
ftp://ftp.suse.com/pub/suse/x86_64/up.../perl-PerlMagick-5.5.7-233.x86_64.rpm
83d2c15b6ba09df08b560d131de2cf5b
source rpm(s):
ftp://ftp.suse.com/pub/suse/x86_64/up...rpm/src/ImageMagick-5.5.7-233.src.rpm
a5c25371a0c311c715dd331309649a57

Original Advisory:
http://www.novell.com/linux/security/advisories/2005_17_imagemagick.html

Other References:
SA14466:
http://secunia.com/advisories/14466/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Today
New advisories: 19
New vulnerabilities: 68
Updated advisories: 62

Moderately // 271 views
Debian update for php5
Moderately // 200 views
Atarone CMS Multiple Vulnerabilities
Moderately // 231 views
Debian update for squid
Less // 237 views
SUSE update for mercurial
Moderately // 277 views
SUSE update for openssh
Less // 220 views
Fedora update for mediawiki

Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Zeroboard Two Vulnerabilities // 58 views
2. Zeroboard Multiple Vulnerabilities // 53 views
3. Debian update for php5 // 53 views
4. Atarone CMS Multiple Vulnerabilities // 40 views
5. Juniper Products Neighbor Discovery Protocol Neighbor Solicitation Vulnerability // 35 views
6. H-Sphere webshell4 Cross-Site Scripting and Request Forgery // 34 views
7. Debian update for squid // 33 views
8. CMME Information Disclosure Security Issues // 32 views
9. MetaGauge Directory Traversal Vulnerability // 28 views
10. SUSE update for mercurial // 27 views