USN-6200-2: ImageMagick vulnerabilities

Published Jul 25, 2024
·
Updated

USN-6200-1 fixed vulnerabilities in ImageMagick. Unfortunately these fixes were incomplete for Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. This update fixes the problem. Original advisory details: It was discovered that ImageMagick incorrectly handled the "-authenticate" option for password-protected PDF files. An attacker could possibly use this issue to inject additional shell commands and perform arbitrary code execution. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-29599) It was discovered that ImageMagick incorrectly handled certain values when processing PDF files. If a user or automated system using ImageMagick were tricked into opening a specially crafted PDF file, an attacker could exploit this to cause a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-20224) Zhang Xiaohui discovered that ImageMagick incorrectly handled certain values when processing image data. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-20241, CVE-2021-20243) It was discovered that ImageMagick incorrectly handled certain values when processing visual effects based image files. By tricking a user into opening a specially crafted image file, an attacker could crash the application causing a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-20244, CVE-2021-20309) It was discovered that ImageMagick incorrectly handled certain values when performing resampling operations. By tricking a user into opening a specially crafted image file, an attacker could crash the application causing a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-20246) It was discovered that ImageMagick incorrectly handled certain values when processing thumbnail image data. By tricking a user into opening a specially crafted image file, an attacker could crash the application causing a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-20312) It was discovered that ImageMagick incorrectly handled memory cleanup when performing certain cryptographic operations. Under certain conditions sensitive cryptographic information could be disclosed. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-20313) It was discovered that ImageMagick did not use the correct rights when specifically excluded by a module policy. An attacker could use this issue to read and write certain restricted files. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-39212) It was discovered that ImageMagick incorrectly handled memory under certain circumstances. If a user were tricked into opening a specially crafted image file, an attacker could possibly exploit this issue to cause a denial of service or other unspecified impact. This issue only affected Ubuntu 20.04 LTS. (CVE-2022-28463, CVE-2022-32545, CVE-2022-32546, CVE-2022-32547) It was discovered that ImageMagick incorrectly handled memory under certain circumstances. If a user were tricked into opening a specially crafted image file, an attacker could possibly exploit this issue to cause a denial of service or other unspecified impact. This issue only affected Ubuntu 22.04 LTS, Ubuntu 22.10, and Ubuntu 23.04. (CVE-2021-3610, CVE-2023-1906, CVE-2023-3428) It was discovered that ImageMagick incorrectly handled certain values when processing specially crafted SVG files. By tricking a user into opening a specially crafted SVG file, an attacker could crash the application causing a denial of service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 22.10, and Ubuntu 23.04. (CVE-2023-1289) It was discovered that ImageMagick incorrectly handled memory under certain circumstances. If a user were tricked into opening a specially crafted tiff file, an attacker could possibly exploit this issue to cause a denial of service or other unspecified impact. This issue only affected Ubuntu 22.04 LTS, Ubuntu 22.10, and Ubuntu 23.04. (CVE-2023-3195) It was discovered that ImageMagick incorrectly handled memory under certain circumstances. If a user were tricked into opening a specially crafted image file, an attacker could possibly exploit this issue to cause a denial of service or other unspecified impact. (CVE-2023-34151)

Affected Software

108 affected componentsFixes available
All of the following
ubuntu/imagemagick<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/imagemagick-6-common<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/imagemagick-6.q16<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/imagemagick-6.q16hdri<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/imagemagick-common<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libimage-magick-perl<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libimage-magick-q16-perl<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libimage-magick-q16hdri-perl<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libmagick++-6-headers<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libmagick++-6.q16-8<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libmagick++-6.q16-dev<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libmagick++-6.q16hdri-8<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libmagick++-6.q16hdri-dev<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libmagick++-dev<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libmagickcore-6-headers<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libmagickcore-6.q16-6<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libmagickcore-6.q16-dev<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libmagickcore-6.q16hdri-6<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libmagickcore-6.q16hdri-dev<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libmagickcore-dev<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libmagickwand-6-headers<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libmagickwand-6.q16-6<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libmagickwand-6.q16-dev<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libmagickwand-6.q16hdri-6<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libmagickwand-6.q16hdri-dev<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libmagickwand-dev<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/perlmagick<8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/imagemagick<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/imagemagick-6-common<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/imagemagick-6.q16<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/imagemagick-6.q16hdri<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/imagemagick-common<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libimage-magick-perl<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libimage-magick-q16-perl<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libimage-magick-q16hdri-perl<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libmagick++-6-headers<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libmagick++-6.q16-8<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libmagick++-6.q16-dev<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libmagick++-6.q16hdri-8<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libmagick++-6.q16hdri-dev<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libmagick++-dev<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libmagickcore-6-headers<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libmagickcore-6.q16-6<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libmagickcore-6.q16-dev<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libmagickcore-6.q16hdri-6<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libmagickcore-6.q16hdri-dev<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libmagickcore-dev<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libmagickwand-6-headers<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libmagickwand-6.q16-6<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libmagickwand-6.q16-dev<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libmagickwand-6.q16hdri-6<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libmagickwand-6.q16hdri-dev<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libmagickwand-dev<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04
All of the following
ubuntu/perlmagick<8:6.9.10.23+dfsg-2.1ubuntu11.10
8:6.9.10.23+dfsg-2.1ubuntu11.10
Ubuntu Ubuntu=20.04

Event History

Jul 25, 2024
Advisory Published
via Ubuntu·12:00 AM

Child vulnerabilities

Contains the following vulnerabilities.

Frequently Asked Questions

1

What is the severity of USN-6200-2?

USN-6200-2 addresses vulnerabilities in ImageMagick that could potentially lead to denial of service or unexpected behavior.

2

How do I fix USN-6200-2?

You can fix USN-6200-2 by updating your ImageMagick packages to version 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5 on Ubuntu 22.04 or appropriate versions on affected Ubuntu releases.

3

What vulnerabilities are fixed in USN-6200-2?

USN-6200-2 fixes incomplete security updates related to handling of the '-authenticate' option in ImageMagick.

4

Which Ubuntu versions are affected by USN-6200-2?

USN-6200-2 affects Ubuntu 20.04 LTS and Ubuntu 22.04 LTS users running specific versions of ImageMagick.

5

Is there a risk to my system if I don't apply USN-6200-2?

Not applying the fixes from USN-6200-2 may leave your system vulnerable to exploitations of the identified vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203