Debian Security Advisory
DSA-2462-2 imagemagick -- several vulnerabilities
- Date Reported:
- 03 May 2012
- Affected Packages:
- imagemagick
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2012-0259, CVE-2012-0260, CVE-2012-1185, CVE-2012-1186, CVE-2012-1610, CVE-2012-1798.
- More information:
-
Several integer overflows and missing input validations were discovered in the ImageMagick image manipulation suite, resulting in the execution of arbitrary code or denial of service.
For the stable distribution (squeeze), this problem has been fixed in version 6.6.0.4-3+squeeze3.
For the unstable distribution (sid), this problem has been fixed in version 8:6.7.4.0-5.
We recommend that you upgrade your imagemagick packages.