First published: Wed Oct 07 2015(Updated: )
An integer truncation flaw leading to a heap-based buffer overflow was found in ImageMagick in pict.c. Detailed stacktrace with reproducer can be found here: <a href="https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1448803">https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1448803</a> Upstream patch for the pict.c problem is a subsection (the pict.c part) of the following commit: <a href="https://github.com/ImageMagick/ImageMagick/commit/0f6fc2d5bf8f500820c3dbcf0d23ee14f2d9f734">https://github.com/ImageMagick/ImageMagick/commit/0f6fc2d5bf8f500820c3dbcf0d23ee14f2d9f734</a> CVE request: <a href="http://seclists.org/oss-sec/2015/q4/45">http://seclists.org/oss-sec/2015/q4/45</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | <6.9.4-0 | |
ImageMagick ImageMagick | >=7.0.0-0<7.0.5-0 | |
Oracle Linux | =6 | |
Oracle Linux | =7 | |
Redhat Enterprise Linux Desktop | =6.0 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux Eus | =7.2 | |
Redhat Enterprise Linux Eus | =7.3 | |
Redhat Enterprise Linux Eus | =7.4 | |
Redhat Enterprise Linux Eus | =7.5 | |
Redhat Enterprise Linux Eus | =7.6 | |
Redhat Enterprise Linux Eus | =7.7 | |
Redhat Enterprise Linux Server | =6.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Server Aus | =7.2 | |
Redhat Enterprise Linux Server Aus | =7.3 | |
Redhat Enterprise Linux Server Aus | =7.4 | |
Redhat Enterprise Linux Server Aus | =7.6 | |
Redhat Enterprise Linux Server Aus | =7.7 | |
Redhat Enterprise Linux Server Tus | =7.2 | |
Redhat Enterprise Linux Server Tus | =7.3 | |
Redhat Enterprise Linux Server Tus | =7.6 | |
Redhat Enterprise Linux Server Tus | =7.7 | |
Redhat Enterprise Linux Workstation | =6.0 | |
Redhat Enterprise Linux Workstation | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.