USN-2990-1: ImageMagick vulnerabilities
USN-2990-1: ImageMagick vulnerabilities Ubuntu Security Notice USN-2990-1 2nd June, 2016 imagemagick vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Several security issues were fixed in ImageMagick. Software description imagemagick – Image manipulation programs and library Details Nikolay Ermishkin and Stewie discovered that ImageMagick incorrectlysanitized untrusted input. A remote attacker could use these issues toexecute arbitrary code. These issues are known as "ImageTragick". Thisupdate disables problematic coders via the /etc/ImageMagick-6/policy.xmlconfiguration file. In certain environments the coders may need to bemanually re-enabled after making sure that ImageMagick does not processuntrusted input. (CVE-2016-3714, CVE-2016-3715, CVE-2016-3716,CVE-2016-3717, CVE-2016-3718) Bob Friesenhahn discovered that ImageMagick allowed injecting commands viaan image file or filename. A remote attacker could use this issue toexecute arbitrary code. (CVE-2016-5118) Update instructions The problem can be corrected [ more… ]