USN-6675-1: ImageProcessing vulnerability
It was discovered that ImageProcessing incorrectly handled series of operations that are coming from unsanitised inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6675-1?
The severity of USN-6675-1 is classified as high due to the potential for arbitrary code execution.
How do I fix USN-6675-1?
To fix USN-6675-1, upgrade the ruby-image-processing package to version 1.10.3-1ubuntu0.22.04.1 for Ubuntu 22.04 or 1.10.3-1ubuntu0.20.04.1 for Ubuntu 20.04.
What systems are affected by USN-6675-1?
USN-6675-1 affects Ubuntu versions 22.04 and 20.04 that are using the ruby-image-processing package.
What could an attacker do with USN-6675-1?
An attacker could exploit the vulnerability in USN-6675-1 to execute arbitrary code by tricking a user into opening a specially crafted input file.
Which package is vulnerable in USN-6675-1?
The vulnerable package in USN-6675-1 is ruby-image-processing, specifically versions prior to 1.10.3-1ubuntu0.22.04.1 and 1.10.3-1ubuntu0.20.04.1.