Description: | Summary: The remote host is missing an update for the 'imagemagick' package(s) announced via the referenced advisory.
Vulnerability Insight: Multiple vulnerabilities has been found and corrected in imagemagick:
Untrusted search path vulnerability in configure.c in ImageMagick before 6.6.5-5, when MAGICKCORE_INSTALLED_SUPPORT is defined, allows local users to gain privileges via a Trojan horse configuration file in the current working directory (CVE-2010-4167).
A flaw was found in the way ImageMagick processed images with malformed Exchangeable image file format (Exif) metadata. An attacker could create a specially-crafted image file that, when opened by a victim, would cause ImageMagick to crash or, potentially, execute arbitrary code (CVE-2012-0247).
A denial of service flaw was found in the way ImageMagick processed images with malformed Exif metadata. An attacker could create a specially-crafted image file that, when opened by a victim, could cause ImageMagick to enter an infinite loop (CVE-2012-0248).
The updated packages have been patched to correct these issues.
Description truncated, please see the referenced URL(s) for more information.
Affected Software/OS: imagemagick on Mandriva Enterprise Server 5.2, Mandriva Linux 2010.1
Solution: Please Install the Updated Packages.
CVSS Score: 6.9
CVSS Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C
|