| Description: | The remote host is missing an update to imagemagick announced via advisory USN-422-1.
A security issue affects the following Ubuntu releases:
Ubuntu 5.10 Ubuntu 6.06 LTS Ubuntu 6.10
This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.
Details follow:
Vladimir Nadvornik discovered that the fix for CVE-2006-5456, released in USN-372-1, did not correctly solve the original flaw in PALM image handling. By tricking a user into processing a specially crafted image with an application that uses imagemagick, an attacker could execute arbitrary code with the user's privileges.
Solution: The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 5.10: libmagick6 6:6.2.3.4-1ubuntu1.6
Ubuntu 6.06 LTS: libmagick9 6:6.2.4.5-0.6ubuntu0.5
Ubuntu 6.10: libmagick9 7:6.2.4.5.dfsg1-0.10ubuntu0.2
In general, a standard system upgrade is sufficient to effect the necessary changes.
http://www.securityspace.com/smysecure/catid.html?in=USN-422-1
Risk factor : Critical |