USN-7440-1: ImageMagick regression
USN-6200-2 fixed a vulnerability in ImageMagick. It was discovered that the fix for CVE-2023-34151 was incomplete. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that ImageMagick incorrectly handled memory under certain circumstances. If a user were tricked into opening a specially crafted image file, an attacker could possibly exploit this issue to cause a denial of service or other unspecified impact. (CVE-2023-34151)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7440-1?
The severity of USN-7440-1 is classified as medium due to the potential risk of memory-related vulnerabilities in ImageMagick.
How do I fix USN-7440-1?
To fix USN-7440-1, update to ImageMagick version 8:6.9.10.23+dfsg-2.1ubuntu11.11 or higher.
Which systems are affected by USN-7440-1?
USN-7440-1 affects Ubuntu 20.04 systems using ImageMagick and its related packages.
What is CVE-2023-34151 related to USN-7440-1?
CVE-2023-34151 refers to a memory handling vulnerability in ImageMagick that was inadequately fixed in a previous update.
What should I do if I cannot apply the USN-7440-1 patch?
If you cannot apply the USN-7440-1 patch, consider mitigating your exposure by restricting access to ImageMagick functionalities.