Ubuntu update for imagemagick



Published: 2023-07-04
Risk High
Patch available YES
Number of vulnerabilities 20
CVE-ID CVE-2020-29599
CVE-2021-20224
CVE-2021-20241
CVE-2021-20243
CVE-2021-20244
CVE-2021-20246
CVE-2021-20309
CVE-2021-20312
CVE-2021-20313
CVE-2021-3610
CVE-2021-39212
CVE-2022-28463
CVE-2022-32545
CVE-2022-32546
CVE-2022-32547
CVE-2023-1289
CVE-2023-1906
CVE-2023-3195
CVE-2023-34151
CVE-2023-3428
CWE-ID CWE-91
CWE-190
CWE-369
CWE-200
CWE-122
CWE-119
CWE-704
CWE-399
CWE-121
CWE-20
Exploitation vector Network
Public exploit Public exploit code for vulnerability #1 is available.
Vulnerable software
Subscribe
Ubuntu
Operating systems & Components / Operating system

libmagickcore-6.q16hdri-3 (Ubuntu package)
Operating systems & Components / Operating system package or component

libmagick++-6.q16-7 (Ubuntu package)
Operating systems & Components / Operating system package or component

libmagickcore-6.q16-3 (Ubuntu package)
Operating systems & Components / Operating system package or component

libmagickwand-6.q16-3 (Ubuntu package)
Operating systems & Components / Operating system package or component

libmagick++-6.q16hdri-7 (Ubuntu package)
Operating systems & Components / Operating system package or component

libmagickcore-6.q16-dev (Ubuntu package)
Operating systems & Components / Operating system package or component

libmagick++-6.q16-8 (Ubuntu package)
Operating systems & Components / Operating system package or component

libmagickcore-dev (Ubuntu package)
Operating systems & Components / Operating system package or component

imagemagick-6.q16hdri (Ubuntu package)
Operating systems & Components / Operating system package or component

libmagickcore-6.q16hdri-6 (Ubuntu package)
Operating systems & Components / Operating system package or component

imagemagick-common (Ubuntu package)
Operating systems & Components / Operating system package or component

libmagick++-6.q16-dev (Ubuntu package)
Operating systems & Components / Operating system package or component

libmagickcore-6.q16-6 (Ubuntu package)
Operating systems & Components / Operating system package or component

libmagickwand-6.q16-dev (Ubuntu package)
Operating systems & Components / Operating system package or component

imagemagick (Ubuntu package)
Operating systems & Components / Operating system package or component

libmagick++-6.q16hdri-8 (Ubuntu package)
Operating systems & Components / Operating system package or component

perlmagick (Ubuntu package)
Operating systems & Components / Operating system package or component

libmagick++-dev (Ubuntu package)
Operating systems & Components / Operating system package or component

libimage-magick-perl (Ubuntu package)
Operating systems & Components / Operating system package or component

libimage-magick-q16-perl (Ubuntu package)
Operating systems & Components / Operating system package or component

libmagickwand-6.q16-6 (Ubuntu package)
Operating systems & Components / Operating system package or component

imagemagick-6-common (Ubuntu package)
Operating systems & Components / Operating system package or component

libmagickcore-6-headers (Ubuntu package)
Operating systems & Components / Operating system package or component

imagemagick-6.q16 (Ubuntu package)
Operating systems & Components / Operating system package or component

libmagickwand-dev (Ubuntu package)
Operating systems & Components / Operating system package or component

libmagick++-6.q16hdri-dev (Ubuntu package)
Operating systems & Components / Operating system package or component

libmagickwand-6.q16-2 (Ubuntu package)
Operating systems & Components / Operating system package or component

libmagickcore-6.q16-2 (Ubuntu package)
Operating systems & Components / Operating system package or component

libmagick++-6.q16-5v5 (Ubuntu package)
Operating systems & Components / Operating system package or component

Vendor Canonical Ltd.

Security Bulletin

This security bulletin contains information about 20 vulnerabilities.

1) XML injection

EUVDB-ID: #VU48940

Risk: High

CVSSv3.1: 8.8 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C]

CVE-ID: CVE-2020-29599

CWE-ID: CWE-91 - XML Injection

Exploit availability: Yes

Description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF files. The user-controlled password was not properly escaped/sanitized and it was therefore possible to inject additional shell commands via coders/pdf.c.

Mitigation

Update the affected package imagemagick to the latest version.

Vulnerable software versions

Ubuntu: 16.04 - 23.04

libmagickcore-6.q16hdri-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16hdri-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-8 (Ubuntu package): before Ubuntu Pro

libmagickcore-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16hdri (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16hdri-6 (Ubuntu package): before Ubuntu Pro

imagemagick-common (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-6 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-8 (Ubuntu package): before Ubuntu Pro

perlmagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-q16-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-6.q16-6 (Ubuntu package): before Ubuntu Pro

imagemagick-6-common (Ubuntu package): before Ubuntu Pro

libmagickcore-6-headers (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-dev (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-5v5 (Ubuntu package): before Ubuntu Pro (Infra-only)

External links

http://ubuntu.com/security/notices/USN-6200-1


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.

2) Integer overflow

EUVDB-ID: #VU67130

Risk: High

CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-20224

CWE-ID: CWE-190 - Integer overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow within the ExportIndexQuantum() function in MagickCore/quantum-export.c. A remote attacker can pass specially crafted image data to the application, trigger an integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Update the affected package imagemagick to the latest version.

Vulnerable software versions

Ubuntu: 16.04 - 23.04

libmagickcore-6.q16hdri-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16hdri-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-8 (Ubuntu package): before Ubuntu Pro

libmagickcore-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16hdri (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16hdri-6 (Ubuntu package): before Ubuntu Pro

imagemagick-common (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-6 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-8 (Ubuntu package): before Ubuntu Pro

perlmagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-q16-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-6.q16-6 (Ubuntu package): before Ubuntu Pro

imagemagick-6-common (Ubuntu package): before Ubuntu Pro

libmagickcore-6-headers (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-dev (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-5v5 (Ubuntu package): before Ubuntu Pro (Infra-only)

External links

http://ubuntu.com/security/notices/USN-6200-1


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Division by zero

EUVDB-ID: #VU61576

Risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-20241

CWE-ID: CWE-369 - Divide By Zero

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a division by zero error within the coders/jp2.c file in ImageMagick. A remote attacker can pass specially crafted data to the application and crash it.

Mitigation

Update the affected package imagemagick to the latest version.

Vulnerable software versions

Ubuntu: 16.04 - 23.04

libmagickcore-6.q16hdri-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16hdri-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-8 (Ubuntu package): before Ubuntu Pro

libmagickcore-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16hdri (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16hdri-6 (Ubuntu package): before Ubuntu Pro

imagemagick-common (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-6 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-8 (Ubuntu package): before Ubuntu Pro

perlmagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-q16-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-6.q16-6 (Ubuntu package): before Ubuntu Pro

imagemagick-6-common (Ubuntu package): before Ubuntu Pro

libmagickcore-6-headers (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-dev (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-5v5 (Ubuntu package): before Ubuntu Pro (Infra-only)

External links

http://ubuntu.com/security/notices/USN-6200-1


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Division by zero

EUVDB-ID: #VU61577

Risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-20243

CWE-ID: CWE-369 - Divide By Zero

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a division by zero error within the MagickCore/resize.c file in ImageMagick. A remote attacker can pass specially crafted data to the application and crash it.

Mitigation

Update the affected package imagemagick to the latest version.

Vulnerable software versions

Ubuntu: 16.04 - 23.04

libmagickcore-6.q16hdri-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16hdri-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-8 (Ubuntu package): before Ubuntu Pro

libmagickcore-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16hdri (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16hdri-6 (Ubuntu package): before Ubuntu Pro

imagemagick-common (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-6 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-8 (Ubuntu package): before Ubuntu Pro

perlmagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-q16-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-6.q16-6 (Ubuntu package): before Ubuntu Pro

imagemagick-6-common (Ubuntu package): before Ubuntu Pro

libmagickcore-6-headers (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-dev (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-5v5 (Ubuntu package): before Ubuntu Pro (Infra-only)

External links

http://ubuntu.com/security/notices/USN-6200-1


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

5) Division by zero

EUVDB-ID: #VU62872

Risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-20244

CWE-ID: CWE-369 - Divide By Zero

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a division by zero error in MagickCore/visual-effects.c . A remote attacker can pass specially crafted data to the application and crash it.

Mitigation

Update the affected package imagemagick to the latest version.

Vulnerable software versions

Ubuntu: 16.04 - 23.04

libmagickcore-6.q16hdri-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16hdri-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-8 (Ubuntu package): before Ubuntu Pro

libmagickcore-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16hdri (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16hdri-6 (Ubuntu package): before Ubuntu Pro

imagemagick-common (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-6 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-8 (Ubuntu package): before Ubuntu Pro

perlmagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-q16-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-6.q16-6 (Ubuntu package): before Ubuntu Pro

imagemagick-6-common (Ubuntu package): before Ubuntu Pro

libmagickcore-6-headers (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-dev (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-5v5 (Ubuntu package): before Ubuntu Pro (Infra-only)

External links

http://ubuntu.com/security/notices/USN-6200-1


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

6) Division by zero

EUVDB-ID: #VU62890

Risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-20246

CWE-ID: CWE-369 - Divide By Zero

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a division by zero error in MagickCore/resample.c. A remote attacker can pass a specially crafted data to the application and crash it.

Mitigation

Update the affected package imagemagick to the latest version.

Vulnerable software versions

Ubuntu: 16.04 - 23.04

libmagickcore-6.q16hdri-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16hdri-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-8 (Ubuntu package): before Ubuntu Pro

libmagickcore-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16hdri (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16hdri-6 (Ubuntu package): before Ubuntu Pro

imagemagick-common (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-6 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-8 (Ubuntu package): before Ubuntu Pro

perlmagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-q16-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-6.q16-6 (Ubuntu package): before Ubuntu Pro

imagemagick-6-common (Ubuntu package): before Ubuntu Pro

libmagickcore-6-headers (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-dev (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-5v5 (Ubuntu package): before Ubuntu Pro (Infra-only)

External links

http://ubuntu.com/security/notices/USN-6200-1


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

7) Division by zero

EUVDB-ID: #VU62868

Risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-20309

CWE-ID: CWE-369 - Divide By Zero

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a division by zero error in the WaveImage() function in MagickCore/visual-effects.c . A remote attacker can pass specially crafted image file to the application and crash it.

Mitigation

Update the affected package imagemagick to the latest version.

Vulnerable software versions

Ubuntu: 16.04 - 23.04

libmagickcore-6.q16hdri-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16hdri-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-8 (Ubuntu package): before Ubuntu Pro

libmagickcore-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16hdri (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16hdri-6 (Ubuntu package): before Ubuntu Pro

imagemagick-common (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-6 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-8 (Ubuntu package): before Ubuntu Pro

perlmagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-q16-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-6.q16-6 (Ubuntu package): before Ubuntu Pro

imagemagick-6-common (Ubuntu package): before Ubuntu Pro

libmagickcore-6-headers (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-dev (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-5v5 (Ubuntu package): before Ubuntu Pro (Infra-only)

External links

http://ubuntu.com/security/notices/USN-6200-1


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

8) Integer overflow

EUVDB-ID: #VU62867

Risk: High

CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-20312

CWE-ID: CWE-190 - Integer overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the WriteTHUMBNAILImage() function in coders/thumbnail.c. A remote attacker can pass specially crafted data to the application, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Update the affected package imagemagick to the latest version.

Vulnerable software versions

Ubuntu: 16.04 - 23.04

libmagickcore-6.q16hdri-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16hdri-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-8 (Ubuntu package): before Ubuntu Pro

libmagickcore-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16hdri (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16hdri-6 (Ubuntu package): before Ubuntu Pro

imagemagick-common (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-6 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-8 (Ubuntu package): before Ubuntu Pro

perlmagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-q16-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-6.q16-6 (Ubuntu package): before Ubuntu Pro

imagemagick-6-common (Ubuntu package): before Ubuntu Pro

libmagickcore-6-headers (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-dev (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-5v5 (Ubuntu package): before Ubuntu Pro (Infra-only)

External links

http://ubuntu.com/security/notices/USN-6200-1


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

9) Information disclosure

EUVDB-ID: #VU62861

Risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-20313

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to potential cipher leak when calculating signatures in TransformSignature() function in MagickCore/signature.c. A remote attacker can gain unauthorized access to sensitive information on the system.

Mitigation

Update the affected package imagemagick to the latest version.

Vulnerable software versions

Ubuntu: 16.04 - 23.04

libmagickcore-6.q16hdri-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16hdri-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-8 (Ubuntu package): before Ubuntu Pro

libmagickcore-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16hdri (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16hdri-6 (Ubuntu package): before Ubuntu Pro

imagemagick-common (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-6 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-8 (Ubuntu package): before Ubuntu Pro

perlmagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-q16-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-6.q16-6 (Ubuntu package): before Ubuntu Pro

imagemagick-6-common (Ubuntu package): before Ubuntu Pro

libmagickcore-6-headers (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-dev (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-5v5 (Ubuntu package): before Ubuntu Pro (Infra-only)

External links

http://ubuntu.com/security/notices/USN-6200-1


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

10) Heap-based buffer overflow

EUVDB-ID: #VU62858

Risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-3610

CWE-ID: CWE-122 - Heap-based Buffer Overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to crash the application.

The vulnerability exists due to an incorrect setting of the pixel array size in ReadTIFFImage() function in coders/tiff.c. A remote attacker can pass specially crafted data to the application, trigger heap-based buffer overflow and perform a denial of service attack.

Mitigation

Update the affected package imagemagick to the latest version.

Vulnerable software versions

Ubuntu: 16.04 - 23.04

libmagickcore-6.q16hdri-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16hdri-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-8 (Ubuntu package): before Ubuntu Pro

libmagickcore-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16hdri (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16hdri-6 (Ubuntu package): before Ubuntu Pro

imagemagick-common (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-6 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-8 (Ubuntu package): before Ubuntu Pro

perlmagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-q16-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-6.q16-6 (Ubuntu package): before Ubuntu Pro

imagemagick-6-common (Ubuntu package): before Ubuntu Pro

libmagickcore-6-headers (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-dev (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-5v5 (Ubuntu package): before Ubuntu Pro (Infra-only)

External links

http://ubuntu.com/security/notices/USN-6200-1


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

11) Exposure of Resource to Wrong Sphere

EUVDB-ID: #VU62889

Risk: Medium

CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-39212

CWE-ID: N/A

Exploit availability: No

Description

The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to improper implementation of security restrictions in the “policy” module when parsing PostScript files. A remote attacker can pass specially crafted PostScript file with customized policy.xml and bypass implemented security restrictions.

Mitigation

Update the affected package imagemagick to the latest version.

Vulnerable software versions

Ubuntu: 16.04 - 23.04

libmagickcore-6.q16hdri-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16hdri-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-8 (Ubuntu package): before Ubuntu Pro

libmagickcore-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16hdri (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16hdri-6 (Ubuntu package): before Ubuntu Pro

imagemagick-common (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-6 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-8 (Ubuntu package): before Ubuntu Pro

perlmagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-q16-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-6.q16-6 (Ubuntu package): before Ubuntu Pro

imagemagick-6-common (Ubuntu package): before Ubuntu Pro

libmagickcore-6-headers (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-dev (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-5v5 (Ubuntu package): before Ubuntu Pro (Infra-only)

External links

http://ubuntu.com/security/notices/USN-6200-1


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

12) Buffer overflow

EUVDB-ID: #VU62851

Risk: High

CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-28463

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing Image files. A remote attacker can pass specially crafted data to the application, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Update the affected package imagemagick to the latest version.

Vulnerable software versions

Ubuntu: 16.04 - 23.04

libmagickcore-6.q16hdri-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16hdri-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-8 (Ubuntu package): before Ubuntu Pro

libmagickcore-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16hdri (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16hdri-6 (Ubuntu package): before Ubuntu Pro

imagemagick-common (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-6 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-8 (Ubuntu package): before Ubuntu Pro

perlmagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-q16-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-6.q16-6 (Ubuntu package): before Ubuntu Pro

imagemagick-6-common (Ubuntu package): before Ubuntu Pro

libmagickcore-6-headers (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-dev (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-5v5 (Ubuntu package): before Ubuntu Pro (Infra-only)

External links

http://ubuntu.com/security/notices/USN-6200-1


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

13) Integer overflow

EUVDB-ID: #VU64947

Risk: Low

CVSSv3.1: 3.8 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-32545

CWE-ID: CWE-190 - Integer overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service attack. 

The vulnerability exists due to integer overflow in coders/psd.c in the ImageMagick when processing crafted or untrusted input. A remote attacker can trick the victim into opening a specially crafted file and perform a denial of service attack. 

Mitigation

Update the affected package imagemagick to the latest version.

Vulnerable software versions

Ubuntu: 16.04 - 23.04

libmagickcore-6.q16hdri-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16hdri-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-8 (Ubuntu package): before Ubuntu Pro

libmagickcore-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16hdri (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16hdri-6 (Ubuntu package): before Ubuntu Pro

imagemagick-common (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-6 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-8 (Ubuntu package): before Ubuntu Pro

perlmagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-q16-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-6.q16-6 (Ubuntu package): before Ubuntu Pro

imagemagick-6-common (Ubuntu package): before Ubuntu Pro

libmagickcore-6-headers (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-dev (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-5v5 (Ubuntu package): before Ubuntu Pro (Infra-only)

External links

http://ubuntu.com/security/notices/USN-6200-1


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

14) Integer overflow

EUVDB-ID: #VU64948

Risk: Low

CVSSv3.1: 3.8 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-32546

CWE-ID: CWE-190 - Integer overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to integer overflow in coders/pcl.c in the ImageMagick when processing crafted or untrusted input. A remote attacker can trick the victim into opening a specially crafted file and perform a denial of service attack.

Mitigation

Update the affected package imagemagick to the latest version.

Vulnerable software versions

Ubuntu: 16.04 - 23.04

libmagickcore-6.q16hdri-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16hdri-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-8 (Ubuntu package): before Ubuntu Pro

libmagickcore-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16hdri (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16hdri-6 (Ubuntu package): before Ubuntu Pro

imagemagick-common (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-6 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-8 (Ubuntu package): before Ubuntu Pro

perlmagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-q16-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-6.q16-6 (Ubuntu package): before Ubuntu Pro

imagemagick-6-common (Ubuntu package): before Ubuntu Pro

libmagickcore-6-headers (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-dev (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-5v5 (Ubuntu package): before Ubuntu Pro (Infra-only)

External links

http://ubuntu.com/security/notices/USN-6200-1


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

15) Type conversion

EUVDB-ID: #VU64949

Risk: Low

CVSSv3.1: 3.8 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-32547

CWE-ID: CWE-704 - Type conversion

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a load of misaligned address for type 'double' in MagickCore/property.c. A remote attacker can trick the victim into opening a specially crafted file and perform a denial of service attack.

Mitigation

Update the affected package imagemagick to the latest version.

Vulnerable software versions

Ubuntu: 16.04 - 23.04

libmagickcore-6.q16hdri-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16hdri-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-8 (Ubuntu package): before Ubuntu Pro

libmagickcore-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16hdri (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16hdri-6 (Ubuntu package): before Ubuntu Pro

imagemagick-common (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-6 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-8 (Ubuntu package): before Ubuntu Pro

perlmagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-q16-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-6.q16-6 (Ubuntu package): before Ubuntu Pro

imagemagick-6-common (Ubuntu package): before Ubuntu Pro

libmagickcore-6-headers (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-dev (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-5v5 (Ubuntu package): before Ubuntu Pro (Infra-only)

External links

http://ubuntu.com/security/notices/USN-6200-1


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

16) Resource management error

EUVDB-ID: #VU74300

Risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-1289

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the application when parsing SVG files. A remote attacker can pass a specially crafted SVG file that contains many render actions and consume all available disk space on the system.

Mitigation

Update the affected package imagemagick to the latest version.

Vulnerable software versions

Ubuntu: 16.04 - 23.04

libmagickcore-6.q16hdri-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16hdri-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-8 (Ubuntu package): before Ubuntu Pro

libmagickcore-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16hdri (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16hdri-6 (Ubuntu package): before Ubuntu Pro

imagemagick-common (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-6 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-8 (Ubuntu package): before Ubuntu Pro

perlmagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-q16-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-6.q16-6 (Ubuntu package): before Ubuntu Pro

imagemagick-6-common (Ubuntu package): before Ubuntu Pro

libmagickcore-6-headers (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-dev (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-5v5 (Ubuntu package): before Ubuntu Pro (Infra-only)

External links

http://ubuntu.com/security/notices/USN-6200-1


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

17) Heap-based buffer overflow

EUVDB-ID: #VU74569

Risk: High

CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-1906

CWE-ID: CWE-122 - Heap-based Buffer Overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in MagickCore/quantum-import.c. A remote attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Update the affected package imagemagick to the latest version.

Vulnerable software versions

Ubuntu: 16.04 - 23.04

libmagickcore-6.q16hdri-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16hdri-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-8 (Ubuntu package): before Ubuntu Pro

libmagickcore-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16hdri (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16hdri-6 (Ubuntu package): before Ubuntu Pro

imagemagick-common (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-6 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-8 (Ubuntu package): before Ubuntu Pro

perlmagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-q16-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-6.q16-6 (Ubuntu package): before Ubuntu Pro

imagemagick-6-common (Ubuntu package): before Ubuntu Pro

libmagickcore-6-headers (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-dev (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-5v5 (Ubuntu package): before Ubuntu Pro (Infra-only)

External links

http://ubuntu.com/security/notices/USN-6200-1


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

18) Stack-based buffer overflow

EUVDB-ID: #VU77451

Risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-3195

CWE-ID: CWE-121 - Stack-based buffer overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack

The vulnerability exists due to a boundary error in coders/tiff.c. A remote attacker can pass a specially crafted TIFF file to the application, trigger a stack overflow and crash the application.

Mitigation

Update the affected package imagemagick to the latest version.

Vulnerable software versions

Ubuntu: 16.04 - 23.04

libmagickcore-6.q16hdri-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16hdri-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-8 (Ubuntu package): before Ubuntu Pro

libmagickcore-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16hdri (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16hdri-6 (Ubuntu package): before Ubuntu Pro

imagemagick-common (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-6 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-8 (Ubuntu package): before Ubuntu Pro

perlmagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-q16-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-6.q16-6 (Ubuntu package): before Ubuntu Pro

imagemagick-6-common (Ubuntu package): before Ubuntu Pro

libmagickcore-6-headers (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-dev (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-5v5 (Ubuntu package): before Ubuntu Pro (Infra-only)

External links

http://ubuntu.com/security/notices/USN-6200-1


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

19) Input validation error

EUVDB-ID: #VU76763

Risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-34151

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted image to the application and perform a denial of service (DoS) attack.

Mitigation

Update the affected package imagemagick to the latest version.

Vulnerable software versions

Ubuntu: 16.04 - 23.04

libmagickcore-6.q16hdri-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16hdri-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-8 (Ubuntu package): before Ubuntu Pro

libmagickcore-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16hdri (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16hdri-6 (Ubuntu package): before Ubuntu Pro

imagemagick-common (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-6 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-8 (Ubuntu package): before Ubuntu Pro

perlmagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-q16-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-6.q16-6 (Ubuntu package): before Ubuntu Pro

imagemagick-6-common (Ubuntu package): before Ubuntu Pro

libmagickcore-6-headers (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-dev (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-5v5 (Ubuntu package): before Ubuntu Pro (Infra-only)

External links

http://ubuntu.com/security/notices/USN-6200-1


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

20) Buffer overflow

EUVDB-ID: #VU77938

Risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-3428

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error when processing TIFF files in coders/tiff.c. A remote attacker can pass a specially crafted TIFF file to the application, trigger memory corruption and perform a denial of service (DoS) attack.

Mitigation

Update the affected package imagemagick to the latest version.

Vulnerable software versions

Ubuntu: 16.04 - 23.04

libmagickcore-6.q16hdri-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-3 (Ubuntu package): before Ubuntu Pro

libmagick++-6.q16hdri-7 (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-8 (Ubuntu package): before Ubuntu Pro

libmagickcore-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16hdri (Ubuntu package): before Ubuntu Pro

libmagickcore-6.q16hdri-6 (Ubuntu package): before Ubuntu Pro

imagemagick-common (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-6 (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-8 (Ubuntu package): before Ubuntu Pro

perlmagick (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libimage-magick-q16-perl (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-6.q16-6 (Ubuntu package): before Ubuntu Pro

imagemagick-6-common (Ubuntu package): before Ubuntu Pro

libmagickcore-6-headers (Ubuntu package): before Ubuntu Pro (Infra-only)

imagemagick-6.q16 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickwand-dev (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16hdri-dev (Ubuntu package): before Ubuntu Pro

libmagickwand-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagickcore-6.q16-2 (Ubuntu package): before Ubuntu Pro (Infra-only)

libmagick++-6.q16-5v5 (Ubuntu package): before Ubuntu Pro (Infra-only)

External links

http://ubuntu.com/security/notices/USN-6200-1


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###