First published: Wed Apr 16 2025(Updated: )
USN-6200-2 fixed a vulnerability in ImageMagick. It was discovered that the fix for CVE-2023-34151 was incomplete. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that ImageMagick incorrectly handled memory under certain circumstances. If a user were tricked into opening a specially crafted image file, an attacker could possibly exploit this issue to cause a denial of service or other unspecified impact. (CVE-2023-34151)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/imagemagick | <8:6.9.10.23+dfsg-2.1ubuntu11.11 | 8:6.9.10.23+dfsg-2.1ubuntu11.11 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/imagemagick-6-common | <8:6.9.10.23+dfsg-2.1ubuntu11.11 | 8:6.9.10.23+dfsg-2.1ubuntu11.11 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/imagemagick-6.q16 | <8:6.9.10.23+dfsg-2.1ubuntu11.11 | 8:6.9.10.23+dfsg-2.1ubuntu11.11 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/imagemagick-6.q16hdri | <8:6.9.10.23+dfsg-2.1ubuntu11.11 | 8:6.9.10.23+dfsg-2.1ubuntu11.11 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/imagemagick-common | <8:6.9.10.23+dfsg-2.1ubuntu11.11 | 8:6.9.10.23+dfsg-2.1ubuntu11.11 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/libmagick++-6.q16-8 | <8:6.9.10.23+dfsg-2.1ubuntu11.11 | 8:6.9.10.23+dfsg-2.1ubuntu11.11 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/libmagick++-6.q16hdri-8 | <8:6.9.10.23+dfsg-2.1ubuntu11.11 | 8:6.9.10.23+dfsg-2.1ubuntu11.11 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/libmagickcore-6.q16-6 | <8:6.9.10.23+dfsg-2.1ubuntu11.11 | 8:6.9.10.23+dfsg-2.1ubuntu11.11 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/libmagickcore-6.q16hdri-6 | <8:6.9.10.23+dfsg-2.1ubuntu11.11 | 8:6.9.10.23+dfsg-2.1ubuntu11.11 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/libmagickwand-6.q16-6 | <8:6.9.10.23+dfsg-2.1ubuntu11.11 | 8:6.9.10.23+dfsg-2.1ubuntu11.11 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/libmagickwand-6.q16hdri-6 | <8:6.9.10.23+dfsg-2.1ubuntu11.11 | 8:6.9.10.23+dfsg-2.1ubuntu11.11 |
Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-7440-1 is classified as medium due to the potential risk of memory-related vulnerabilities in ImageMagick.
To fix USN-7440-1, update to ImageMagick version 8:6.9.10.23+dfsg-2.1ubuntu11.11 or higher.
USN-7440-1 affects Ubuntu 20.04 systems using ImageMagick and its related packages.
CVE-2023-34151 refers to a memory handling vulnerability in ImageMagick that was inadequately fixed in a previous update.
If you cannot apply the USN-7440-1 patch, consider mitigating your exposure by restricting access to ImageMagick functionalities.