USN-6960-1: RMagick vulnerability
Published Aug 14, 2024
·Updated
Nick Browning discovered that RMagick incorrectly handled memory under certain operations. An attacker could possibly use this issue to cause a denial of service through memory exhaustion.
Affected Software
4 affected componentsFixes available
All of the following
ubuntu/ruby-rmagick<4.2.3-2ubuntu0.22.04.1~esm2
4.2.3-2ubuntu0.22.04.1~esm2
Ubuntu Ubuntu=22.04
All of the following
ubuntu/ruby-rmagick<2.16.0-6ubuntu0.1
2.16.0-6ubuntu0.1
Ubuntu Ubuntu=20.04
Event History
Aug 14, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6960-1?
The severity of USN-6960-1 is classified as a denial of service due to memory exhaustion issues in RMagick.
2
How do I fix USN-6960-1?
To fix USN-6960-1, you should upgrade ruby-rmagick to the latest version available for your Ubuntu release.
3
What software is affected by USN-6960-1?
USN-6960-1 affects ruby-rmagick versions up to 4.2.3-2ubuntu0.22.04.1 for Ubuntu 22.04 and up to 2.16.0-6ubuntu0.1 for Ubuntu 20.04.
4
What are the potential impacts of USN-6960-1?
The potential impact of USN-6960-1 includes denial of service attacks that may disrupt services by exhausting memory resources.
5
Who discovered the vulnerability in USN-6960-1?
The vulnerability addressed in USN-6960-1 was discovered by Nick Browning.