ImageMagick-6.5.4.7-6.AXS4

エラータID: AXSA:2012-659:01

Release date: 
Friday, July 27, 2012 - 16:25
Subject: 
ImageMagick-6.5.4.7-6.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

ImageMagick is an image display and manipulation tool for the X Window System. ImageMagick can read and write JPEG, TIFF, PNM, GIF, and Photo CD image formats. It can resize, rotate, sharpen, color reduce, or add special effects to an image, and when finished you can either save the completed work in the original format or a different one. ImageMagick also includes command line programs for creating animated or transparent .gifs, creating composite images, creating thumbnail images, and more.

ImageMagick is one of your choices if you need a program to manipulate and display images. If you want to develop your own applications which use ImageMagick code or APIs, you need to install ImageMagick-devel as well.

Security issues fixed with this release:

• CVE-2010-4167
Untrusted search path vulnerability in configure.c in ImageMagick before 6.6.5-5, when MAGICKCORE_INSTALLED_SUPPORT is defined, allows local users to gain privileges via a Trojan horse configuration file in the current working directory.

• CVE-2012-0247
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0 of an image.

• CVE-2012-0248
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.

• CVE-2012-0259
The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG file, which triggers an out-of-bounds read.

• CVE-2012-0260
The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers.

• CVE-2012-1798
The TIFFGetEXIFProperties function in coders/tiff.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted EXIF IFD in a TIFF image.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. ImageMagick-6.5.4.7-6.AXS4.src.rpm
    MD5: 38112319d959da0886d6bf412ab4f8d4
    SHA-256: 331a435f73b0b5302083e95416454018d135e2aa52c014c01ceae8dde58e887d
    Size: 5.64 MB

Asianux Server 4 for x86
  1. ImageMagick-6.5.4.7-6.AXS4.i686.rpm
    MD5: 97015fc221af8e1a3c05eb1ad70f951f
    SHA-256: 2cf7bdfa8ff8d53bbe4787a0e091d091cde1aa70ee40c6bdb1b421e69e506bf6
    Size: 1.68 MB
  2. ImageMagick-c++-6.5.4.7-6.AXS4.i686.rpm
    MD5: d2bc0e4afc04e3beef61237679a524d4
    SHA-256: 56011419788ffe4d85672c7eb6fd8c7dfe6947addc26797a4cdc7994e697d458
    Size: 141.74 kB

Asianux Server 4 for x86_64
  1. ImageMagick-6.5.4.7-6.AXS4.x86_64.rpm
    MD5: e3ced3e18a1fdf170a0a5ba4d5d48590
    SHA-256: 90b27822d1aded829e8a65deccdc3783a178db775812fa41f3821f9c79b3d022
    Size: 1.70 MB
  2. ImageMagick-c++-6.5.4.7-6.AXS4.x86_64.rpm
    MD5: 8b360fb08699300566527736a33c7534
    SHA-256: 548e2ebd3540a2b384240096a0656e62f1a0d62e4080858595905e7c8c8605cd
    Size: 136.20 kB
  3. ImageMagick-6.5.4.7-6.AXS4.i686.rpm
    MD5: 97015fc221af8e1a3c05eb1ad70f951f
    SHA-256: 2cf7bdfa8ff8d53bbe4787a0e091d091cde1aa70ee40c6bdb1b421e69e506bf6
    Size: 1.68 MB