Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.57586
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1213)
Summary:The remote host is missing an update for the Debian 'imagemagick' package(s) announced via the DSA-1213 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'imagemagick' package(s) announced via the DSA-1213 advisory.

Vulnerability Insight:
Several remote vulnerabilities have been discovered in Imagemagick, a collection of image manipulation programs, which may lead to the execution of arbitrary code. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2006-0082

Daniel Kobras discovered that Imagemagick is vulnerable to format string attacks in the filename parsing code.

CVE-2006-4144

Damian Put discovered that Imagemagick is vulnerable to buffer overflows in the module for SGI images.

CVE-2006-5456

M Joonas Pihlaja discovered that Imagemagick is vulnerable to buffer overflows in the module for DCM and PALM images.

CVE-2006-5868

Daniel Kobras discovered that Imagemagick is vulnerable to buffer overflows in the module for SGI images.

This update also addresses regressions in the XCF codec, which were introduced in the previous security update.

For the stable distribution (sarge) these problems have been fixed in version 6:6.0.6.2-2.8.

For the upcoming stable distribution (etch) these problems have been fixed in version 7:6.2.4.5.dfsg1-0.11.

For the unstable distribution (sid) these problems have been fixed in version 7:6.2.4.5.dfsg1-0.11.

We recommend that you upgrade your imagemagick packages.

Affected Software/OS:
'imagemagick' package(s) on Debian 3.1.

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2006-0082
BugTraq ID: 12717
http://www.securityfocus.com/bid/12717
Bugtraq: 20061127 rPSA-2006-0218-1 ImageMagick (Google Search)
http://www.securityfocus.com/archive/1/452718/100/100/threaded
Debian Security Information: DSA-1213 (Google Search)
http://www.debian.org/security/2006/dsa-1213
http://www.gentoo.org/security/en/glsa/glsa-200602-06.xml
http://www.gentoo.org/security/en/glsa/glsa-200602-13.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:024
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10717
RedHat Security Advisories: RHSA-2006:0178
http://rhn.redhat.com/errata/RHSA-2006-0178.html
http://securitytracker.com/id?1015623
http://secunia.com/advisories/18261
http://secunia.com/advisories/18607
http://secunia.com/advisories/18851
http://secunia.com/advisories/18871
http://secunia.com/advisories/19030
http://secunia.com/advisories/19183
http://secunia.com/advisories/19408
http://secunia.com/advisories/22998
http://secunia.com/advisories/23090
http://secunia.com/advisories/28800
SGI Security Advisory: 20060301-01-U
ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.341682
http://securityreason.com/securityalert/500
http://sunsolve.sun.com/search/document.do?assetkey=1-26-231321-1
SuSE Security Announcement: SUSE-SR:2006:006 (Google Search)
http://www.novell.com/linux/security/advisories/2006_06_sr.html
http://www.ubuntu.com/usn/usn-246-1
http://www.vupen.com/english/advisories/2008/0412
Common Vulnerability Exposure (CVE) ID: CVE-2006-4144
BugTraq ID: 19507
http://www.securityfocus.com/bid/19507
Bugtraq: 20060814 [Overflow.pl] ImageMagick ReadSGIImage() Heap Overflow (Google Search)
http://www.securityfocus.com/archive/1/443208/100/0/threaded
Bugtraq: 20060816 Re: [Overflow.pl] ImageMagick ReadSGIImage() Heap Overflow (Google Search)
http://www.securityfocus.com/archive/1/443362/100/0/threaded
http://security.gentoo.org/glsa/glsa-200609-14.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:155
http://www.overflow.pl/adv/imsgiheap.txt
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11129
http://www.redhat.com/support/errata/RHSA-2006-0633.html
http://securitytracker.com/id?1016699
http://secunia.com/advisories/21462
http://secunia.com/advisories/21525
http://secunia.com/advisories/21621
http://secunia.com/advisories/21671
http://secunia.com/advisories/21679
http://secunia.com/advisories/21832
http://secunia.com/advisories/22036
http://secunia.com/advisories/22096
SGI Security Advisory: 20060901-01-P
ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc
http://securityreason.com/securityalert/1385
SuSE Security Announcement: SUSE-SA:2006:050 (Google Search)
http://www.novell.com/linux/security/advisories/2006_50_imagemagick.html
http://www.ubuntu.com/usn/usn-337-1
XForce ISS Database: imagemagick-readsgiimage-bo(28372)
https://exchange.xforce.ibmcloud.com/vulnerabilities/28372
Common Vulnerability Exposure (CVE) ID: CVE-2006-5456
BugTraq ID: 20707
http://www.securityfocus.com/bid/20707
Bugtraq: 20070208 rPSA-2007-0029-1 ImageMagick (Google Search)
http://www.securityfocus.com/archive/1/459507/100/0/threaded
http://security.gentoo.org/glsa/glsa-200611-07.xml
http://security.gentoo.org/glsa/glsa-200611-19.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:193
http://www.mandriva.com/security/advisories?name=MDKSA-2007:041
http://www.osvdb.org/29990
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9765
http://www.redhat.com/support/errata/RHSA-2007-0015.html
http://secunia.com/advisories/22569
http://secunia.com/advisories/22572
http://secunia.com/advisories/22601
http://secunia.com/advisories/22604
http://secunia.com/advisories/22819
http://secunia.com/advisories/22834
http://secunia.com/advisories/23121
http://secunia.com/advisories/24186
http://secunia.com/advisories/24196
http://secunia.com/advisories/24284
http://secunia.com/advisories/24458
SGI Security Advisory: 20070201-01-P
ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.352092
SuSE Security Announcement: SUSE-SA:2006:066 (Google Search)
http://www.novell.com/linux/security/advisories/2006_66_imagemagick.html
SuSE Security Announcement: SUSE-SR:2007:003 (Google Search)
http://www.novell.com/linux/security/advisories/2007_3_sr.html
http://www.ubuntu.com/usn/usn-372-1
http://www.ubuntu.com/usn/usn-422-1
http://www.vupen.com/english/advisories/2006/4170
http://www.vupen.com/english/advisories/2006/4171
XForce ISS Database: imagemagick-graphicsmagick-palm-bo(29816)
https://exchange.xforce.ibmcloud.com/vulnerabilities/29816
Common Vulnerability Exposure (CVE) ID: CVE-2006-5868
BugTraq ID: 21185
http://www.securityfocus.com/bid/21185
http://www.mandriva.com/security/advisories?name=MDKSA-2006:223
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10612
http://secunia.com/advisories/23101
http://secunia.com/advisories/23219
http://www.ubuntu.com/usn/usn-386-1
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.