what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Mandriva Linux Security Advisory 2012-077

Mandriva Linux Security Advisory 2012-077
Posted May 17, 2012
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2012-077 - Untrusted search path vulnerability in configure.c in ImageMagick before 6.6.5-5, when MAGICKCORE_INSTALLED_SUPPORT is defined, allows local users to gain privileges via a Trojan horse configuration file in the current working directory. A flaw was found in the way ImageMagick processed images with malformed Exchangeable image file format metadata. An attacker could create a specially-crafted image file that, when opened by a victim, would cause ImageMagick to crash or, potentially, execute arbitrary code. A denial of service flaw was found in the way ImageMagick processed images with malformed Exif metadata. An attacker could create a specially-crafted image file that, when opened by a victim, could cause ImageMagick to enter an infinite loop. Various other issues have also been addressed.

tags | advisory, denial of service, arbitrary, local, trojan
systems | linux, mandriva
advisories | CVE-2010-4167, CVE-2012-0247, CVE-2012-0248, CVE-2012-1185, CVE-2012-0259, CVE-2012-0260, CVE-2012-1798
SHA-256 | d7de3f7e0b80f09045f1b2c5f542725b115d3f5c08f7a893d8351dc7200e188a

Mandriva Linux Security Advisory 2012-077

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2012:077
http://www.mandriva.com/security/
_______________________________________________________________________

Package : imagemagick
Date : May 17, 2012
Affected: 2010.1, Enterprise Server 5.0
_______________________________________________________________________

Problem Description:

Multiple vulnerabilities has been found and corrected in imagemagick:

Untrusted search path vulnerability in configure.c in ImageMagick
before 6.6.5-5, when MAGICKCORE_INSTALLED_SUPPORT is defined, allows
local users to gain privileges via a Trojan horse configuration file
in the current working directory (CVE-2010-4167).

A flaw was found in the way ImageMagick processed images with malformed
Exchangeable image file format (Exif) metadata. An attacker could
create a specially-crafted image file that, when opened by a victim,
would cause ImageMagick to crash or, potentially, execute arbitrary
code (CVE-2012-0247).

A denial of service flaw was found in the way ImageMagick processed
images with malformed Exif metadata. An attacker could create a
specially-crafted image file that, when opened by a victim, could
cause ImageMagick to enter an infinite loop (CVE-2012-0248).

The original fix for CVE-2012-0247 failed to check for the possibility
of an integer overflow when computing the sum of number_bytes and
offset. This resulted in a wrap around into a value smaller than
length, making original CVE-2012-0247 introduced length check still
to be possible to bypass, leading to memory corruption (CVE-2012-1185).

An integer overflow flaw was found in the way ImageMagick processed
certain Exif tags with a large components count. An attacker
could create a specially-crafted image file that, when opened by a
victim, could cause ImageMagick to access invalid memory and crash
(CVE-2012-0259).

A denial of service flaw was found in the way ImageMagick decoded
certain JPEG images. A remote attacker could provide a JPEG image with
specially-crafted sequences of RST0 up to RST7 restart markers (used
to indicate the input stream to be corrupted), which once processed
by ImageMagick, would cause it to consume excessive amounts of memory
and CPU time (CVE-2012-0260).

An out-of-bounds buffer read flaw was found in the way ImageMagick
processed certain TIFF image files. A remote attacker could provide
a TIFF image with a specially-crafted Exif IFD value (the set of tags
for recording Exif-specific attribute information), which once opened
by ImageMagick, would cause it to crash (CVE-2012-1798).

The updated packages have been patched to correct these issues.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4167
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0247
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0248
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1185
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0259
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0260
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1798
_______________________________________________________________________

Updated Packages:

Mandriva Linux 2010.1:
4ff09ac510c672499ee00a416edfc2db 2010.1/i586/imagemagick-6.6.1.5-2.1mdv2010.2.i586.rpm
7373862037711c4b07776f34ff3f4be0 2010.1/i586/imagemagick-desktop-6.6.1.5-2.1mdv2010.2.i586.rpm
8b6a91e231b75db0c0c621649f88290f 2010.1/i586/imagemagick-doc-6.6.1.5-2.1mdv2010.2.i586.rpm
f0b6618f6538194cf7052214d68e2871 2010.1/i586/libmagick3-6.6.1.5-2.1mdv2010.2.i586.rpm
a520984667c9e98de7652fe597cd193d 2010.1/i586/libmagick-devel-6.6.1.5-2.1mdv2010.2.i586.rpm
7c21957250e196d6a539edfff75ef105 2010.1/i586/perl-Image-Magick-6.6.1.5-2.1mdv2010.2.i586.rpm
56aa3fca43507cbdb5fe248c9314d860 2010.1/SRPMS/imagemagick-6.6.1.5-2.1mdv2010.2.src.rpm

Mandriva Linux 2010.1/X86_64:
2409ce33960122226551d2becad53fca 2010.1/x86_64/imagemagick-6.6.1.5-2.1mdv2010.2.x86_64.rpm
93c7a6840fdc4886239e00b6d4e83098 2010.1/x86_64/imagemagick-desktop-6.6.1.5-2.1mdv2010.2.x86_64.rpm
32896b93d2bd840d8656a04876236a51 2010.1/x86_64/imagemagick-doc-6.6.1.5-2.1mdv2010.2.x86_64.rpm
e6f4557debbd9cfc3e44d81be6536075 2010.1/x86_64/lib64magick3-6.6.1.5-2.1mdv2010.2.x86_64.rpm
4386810c4640ea9e3561d196f0d00ff2 2010.1/x86_64/lib64magick-devel-6.6.1.5-2.1mdv2010.2.x86_64.rpm
6cde8d3590fc4a3f1e6cf74d8c42c7ed 2010.1/x86_64/perl-Image-Magick-6.6.1.5-2.1mdv2010.2.x86_64.rpm
56aa3fca43507cbdb5fe248c9314d860 2010.1/SRPMS/imagemagick-6.6.1.5-2.1mdv2010.2.src.rpm

Mandriva Enterprise Server 5:
74c481999cfa56013ef04ffba6fc5945 mes5/i586/imagemagick-6.4.2.10-5.3mdvmes5.2.i586.rpm
2b591de902a76d961e483ad447e299b9 mes5/i586/imagemagick-desktop-6.4.2.10-5.3mdvmes5.2.i586.rpm
b3353d5b6ac13de56b299dbd1dc1f1d7 mes5/i586/imagemagick-doc-6.4.2.10-5.3mdvmes5.2.i586.rpm
a5be187b2d15e57068717be451dbeedd mes5/i586/libmagick1-6.4.2.10-5.3mdvmes5.2.i586.rpm
fd04200438ae525dbd594ef8adf74150 mes5/i586/libmagick-devel-6.4.2.10-5.3mdvmes5.2.i586.rpm
12bc440241c35517d681c316e426a55d mes5/i586/perl-Image-Magick-6.4.2.10-5.3mdvmes5.2.i586.rpm
25c05027ec8e9122a9fe18b14d949ebe mes5/SRPMS/imagemagick-6.4.2.10-5.3mdvmes5.2.src.rpm

Mandriva Enterprise Server 5/X86_64:
81b69f7bb9d3e4237a426cae23e21970 mes5/x86_64/imagemagick-6.4.2.10-5.3mdvmes5.2.x86_64.rpm
a97f42e2875a0ebc3bc487c657eda457 mes5/x86_64/imagemagick-desktop-6.4.2.10-5.3mdvmes5.2.x86_64.rpm
92d5364d9e74c865fdfb91643247f8c9 mes5/x86_64/imagemagick-doc-6.4.2.10-5.3mdvmes5.2.x86_64.rpm
b100d380eb002a3244e1ee661b1633f5 mes5/x86_64/lib64magick1-6.4.2.10-5.3mdvmes5.2.x86_64.rpm
d3b569df24eeae5ad3d0c7119e91df8a mes5/x86_64/lib64magick-devel-6.4.2.10-5.3mdvmes5.2.x86_64.rpm
2f3012e2b94ae58b6bdcf513afbda0ae mes5/x86_64/perl-Image-Magick-6.4.2.10-5.3mdvmes5.2.x86_64.rpm
25c05027ec8e9122a9fe18b14d949ebe mes5/SRPMS/imagemagick-6.4.2.10-5.3mdvmes5.2.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iD8DBQFPtM6RmqjQ0CJFipgRAtLcAJ0eCJy5lHqxUtx8HGiXR39Nc9w70QCfU3NR
aMRrLfbQbqenE7QZQBGaC6s=
=fXtt
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    16 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close