First published: Thu Nov 14 2019(Updated: )
It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privileges of the user invoking the program.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/imagemagick | <8:6.9.10.23+dfsg-2.1ubuntu3.1 | 8:6.9.10.23+dfsg-2.1ubuntu3.1 |
=19.10 | ||
All of | ||
ubuntu/imagemagick-6.q16 | <8:6.9.10.23+dfsg-2.1ubuntu3.1 | 8:6.9.10.23+dfsg-2.1ubuntu3.1 |
=19.10 | ||
All of | ||
ubuntu/libmagick++-6.q16-8 | <8:6.9.10.23+dfsg-2.1ubuntu3.1 | 8:6.9.10.23+dfsg-2.1ubuntu3.1 |
=19.10 | ||
All of | ||
ubuntu/libmagickcore-6.q16-6 | <8:6.9.10.23+dfsg-2.1ubuntu3.1 | 8:6.9.10.23+dfsg-2.1ubuntu3.1 |
=19.10 | ||
All of | ||
ubuntu/libmagickcore-6.q16-6-extra | <8:6.9.10.23+dfsg-2.1ubuntu3.1 | 8:6.9.10.23+dfsg-2.1ubuntu3.1 |
=19.10 | ||
All of | ||
ubuntu/imagemagick | <8:6.9.10.14+dfsg-7ubuntu2.3 | 8:6.9.10.14+dfsg-7ubuntu2.3 |
=19.04 | ||
All of | ||
ubuntu/imagemagick-6.q16 | <8:6.9.10.14+dfsg-7ubuntu2.3 | 8:6.9.10.14+dfsg-7ubuntu2.3 |
=19.04 | ||
All of | ||
ubuntu/libmagick++-6.q16-8 | <8:6.9.10.14+dfsg-7ubuntu2.3 | 8:6.9.10.14+dfsg-7ubuntu2.3 |
=19.04 | ||
All of | ||
ubuntu/libmagickcore-6.q16-6 | <8:6.9.10.14+dfsg-7ubuntu2.3 | 8:6.9.10.14+dfsg-7ubuntu2.3 |
=19.04 | ||
All of | ||
ubuntu/libmagickcore-6.q16-6-extra | <8:6.9.10.14+dfsg-7ubuntu2.3 | 8:6.9.10.14+dfsg-7ubuntu2.3 |
=19.04 | ||
All of | ||
ubuntu/imagemagick | <8:6.9.7.4+dfsg-16ubuntu6.8 | 8:6.9.7.4+dfsg-16ubuntu6.8 |
=18.04 | ||
All of | ||
ubuntu/imagemagick-6.q16 | <8:6.9.7.4+dfsg-16ubuntu6.8 | 8:6.9.7.4+dfsg-16ubuntu6.8 |
=18.04 | ||
All of | ||
ubuntu/libmagick++-6.q16-7 | <8:6.9.7.4+dfsg-16ubuntu6.8 | 8:6.9.7.4+dfsg-16ubuntu6.8 |
=18.04 | ||
All of | ||
ubuntu/libmagickcore-6.q16-3 | <8:6.9.7.4+dfsg-16ubuntu6.8 | 8:6.9.7.4+dfsg-16ubuntu6.8 |
=18.04 | ||
All of | ||
ubuntu/libmagickcore-6.q16-3-extra | <8:6.9.7.4+dfsg-16ubuntu6.8 | 8:6.9.7.4+dfsg-16ubuntu6.8 |
=18.04 | ||
All of | ||
ubuntu/imagemagick | <8:6.8.9.9-7ubuntu5.15 | 8:6.8.9.9-7ubuntu5.15 |
=16.04 | ||
All of | ||
ubuntu/imagemagick-6.q16 | <8:6.8.9.9-7ubuntu5.15 | 8:6.8.9.9-7ubuntu5.15 |
=16.04 | ||
All of | ||
ubuntu/libmagick++-6.q16-5v5 | <8:6.8.9.9-7ubuntu5.15 | 8:6.8.9.9-7ubuntu5.15 |
=16.04 | ||
All of | ||
ubuntu/libmagickcore-6.q16-2 | <8:6.8.9.9-7ubuntu5.15 | 8:6.8.9.9-7ubuntu5.15 |
=16.04 | ||
All of | ||
ubuntu/libmagickcore-6.q16-2-extra | <8:6.8.9.9-7ubuntu5.15 | 8:6.8.9.9-7ubuntu5.15 |
=16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The vulnerability ID for these ImageMagick vulnerabilities is CVE-2019-12974, CVE-2019-12975, and CVE-2019-12976.
The severity of the ImageMagick vulnerabilities is not specified.
These vulnerabilities in ImageMagick could allow an attacker to cause a denial of service or possibly execute code with the privileges of the user or automated system using ImageMagick.
These vulnerabilities affect Ubuntu versions 19.10, 19.04, 18.04, and 16.04.
To fix the ImageMagick vulnerabilities, you should update to version 8:6.9.10.23+dfsg-2.1ubuntu3.1 for the affected packages.