![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.56210 |
Category: | Debian Local Security Checks |
Title: | Debian Security Advisory DSA 957-1 (imagemagick) |
Summary: | The remote host is missing an update to imagemagick announced via advisory DSA 957-1. Florian Weimer discovered that delegate code in ImageMagick is vulnerable to shell command injection using specially crafted file names. This allows attackers to encode commands inside of graphic commands. With some user interaction, this is exploitable through Gnus and Thunderbird. For the old stable distribution (woody) this problem has been fixed in version 5.4.4.5-1woody7.;; This VT has been deprecated and merged into the VT 'Debian: Security Advisory (DSA-957)' (OID: 1.3.6.1.4.1.25623.1.0.56217). |
Description: | Summary: The remote host is missing an update to imagemagick announced via advisory DSA 957-1. Florian Weimer discovered that delegate code in ImageMagick is vulnerable to shell command injection using specially crafted file names. This allows attackers to encode commands inside of graphic commands. With some user interaction, this is exploitable through Gnus and Thunderbird. For the old stable distribution (woody) this problem has been fixed in version 5.4.4.5-1woody7. This VT has been deprecated and merged into the VT 'Debian: Security Advisory (DSA-957)' (OID: 1.3.6.1.4.1.25623.1.0.56217). Solution: For the stable distribution (sarge) this problem has been fixed in version 6.0.6.2-2.5. For the unstable distribution (sid) this problem has been fixed in version 6.2.4.5-0.6. We recommend that you upgrade your imagemagick packages. CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2005-4601 BugTraq ID: 16093 http://www.securityfocus.com/bid/16093 Bugtraq: 20061127 rPSA-2006-0218-1 ImageMagick (Google Search) http://www.securityfocus.com/archive/1/452718/100/100/threaded Debian Security Information: DSA-957 (Google Search) http://www.debian.org/security/2006/dsa-957 http://www.mandriva.com/security/advisories?name=MDKSA-2006:024 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345238 http://www.osvdb.org/22121 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10353 RedHat Security Advisories: RHSA-2006:0178 http://rhn.redhat.com/errata/RHSA-2006-0178.html http://secunia.com/advisories/18261 http://secunia.com/advisories/18607 http://secunia.com/advisories/18631 http://secunia.com/advisories/18871 http://secunia.com/advisories/19183 http://secunia.com/advisories/19408 http://secunia.com/advisories/23090 http://secunia.com/advisories/28800 SGI Security Advisory: 20060301-01-U ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.341682 http://sunsolve.sun.com/search/document.do?assetkey=1-26-231321-1 SuSE Security Announcement: SUSE-SR:2006:006 (Google Search) http://www.novell.com/linux/security/advisories/2006_06_sr.html http://www.ubuntu.com/usn/usn-246-1 http://www.vupen.com/english/advisories/2008/0412 XForce ISS Database: imagemagick-filename-command-injection(23927) https://exchange.xforce.ibmcloud.com/vulnerabilities/23927 |
Copyright | Copyright (C) 2008 E-Soft Inc. |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |