OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
rPSA-2006-0218-1 ImageMagick

From: rPath Update Announcements (announce-noreplyrpath.com)
Date: Mon Nov 27 2006 - 09:42:59 CST


rPath Security Advisory: 2006-0218-1
Published: 2006-11-27
Products: rPath Linux 1
Rating: Major
Exposure Level Classification:
    Indirect User Deterministic Unauthorized Access
Updated Versions:
    ImageMagick=/conary.rpath.comrpl:devel//1/6.2.3.3-3.4-1

References:
    http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5456
    http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4601
    http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0082
    https://issues.rpath.com/browse/RPL-811
    https://issues.rpath.com/browse/RPL-389

Description:
    Previous versions of the ImageMagick package contained multiple
    vulnerabilities. Attacker-supplied malformed image files may
    allow arbitrary code execution as the running user.