ALT-PU-2021-1001-1
Package ImageMagick updated to version 6.9.11.53-alt1 for branch sisyphus in task 264282.
Closed vulnerabilities
BDU:2021-01009
Уязвимость консольного графического редактора ImageMagick, вызванная переполнением буфера, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации
BDU:2021-03444
Уязвимость опции -authenticate консольного графического редактора ImageMagick, связанная с ошибками в обработке XML-запросов, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2020-27752
A flaw was found in ImageMagick in MagickCore/quantum-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger a heap buffer overflow. This would most likely lead to an impact to application availability, but could potentially lead to an impact to data integrity as well. This flaw affects ImageMagick versions prior to 7.0.9-0.
Modified: 2024-11-21
CVE-2020-29599
ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF files. The user-controlled password was not properly escaped/sanitized and it was therefore possible to inject additional shell commands via coders/pdf.c.
- https://github.com/ImageMagick/ImageMagick/discussions/2851
- https://github.com/ImageMagick/ImageMagick/discussions/2851
- https://insert-script.blogspot.com/2020/11/imagemagick-shell-injection-via-pdf.html
- https://insert-script.blogspot.com/2020/11/imagemagick-shell-injection-via-pdf.html
- [debian-lts-announce] 20210112 [SECURITY] [DLA 2523-1] imagemagick security update
- [debian-lts-announce] 20210112 [SECURITY] [DLA 2523-1] imagemagick security update
- [debian-lts-announce] 20230311 [SECURITY] [DLA 3357-1] imagemagick security update
- [debian-lts-announce] 20230311 [SECURITY] [DLA 3357-1] imagemagick security update
- GLSA-202101-36
- GLSA-202101-36