GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Wed Nov 30, 2016 10:26 pm Post subject: [ GLSA 201611-21 ] ImageMagick |
|
|
Gentoo Linux Security Advisory
Title: ImageMagick: Multiple vulnerabilities (GLSA 201611-21)
Severity: normal
Exploitable: remote
Date: November 30, 2016
Bug(s): #581990, #593526, #593530, #593532, #595200, #596002, #596004
ID: 201611-21
Synopsis
Multiple vulnerabilities have been found in ImageMagick, the worst
of which allows remote attackers to execute arbitrary code.
Background
ImageMagick is a collection of tools and libraries for many image
formats.
Affected Packages
Package: media-gfx/imagemagick
Vulnerable: < 6.9.6.2
Unaffected: >= 6.9.6.2
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in ImageMagick. Please
review the CVE identifiers referenced below for details.
Impact
A remote attacker could possibly execute arbitrary code with the
privileges of the process or cause a Denial of Service condition.
Workaround
There is no known workaround at this time.
Resolution
All ImageMagick users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=media-gfx/imagemagick-6.9.6.2"
|
References
CVE-2016-3714
CVE-2016-3715
CVE-2016-3716
CVE-2016-3717
CVE-2016-3718
CVE-2016-5010
CVE-2016-5842
CVE-2016-6491
CVE-2016-7799
CVE-2016-7906 |
|