GraphicsMagick Bugs in Multiple Readers Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1020413
|
|
SecurityTracker URL: http://securitytracker.com/id?1020413
|
|
CVE Reference: CVE-2008-3134
(Links to External Site)
|
Updated: Aug 6 2008
|
Original Entry Date: Jul 2 2008
|
Impact: Denial of service via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): prior to 1.2.4
|
Description: A vulnerability was reported in GraphicsMagick. A remote user can cause denial of service conditions.
A remote user can create a specially crafted file that, when processed by the target application, will cause the target application
to crash.
The AVI, AVS, DCM, EPT, FITS, MTV, PALM, RLA, and TGA readers are affected. The GetImageCharacteristics() is affected.
|
Impact: A remote user can create a file that, when processed by the target application, will cause the target application to crash.
|
Solution: The vendor has issued a fixed version (1.2.4).
The vendor's advisory is available at:
http://sourceforge.net/project/shownotes.php?release_id=610253
|
Vendor URL: www.graphicsmagick.org/ (Links to External Site)
|
Cause: Not specified
|
Underlying OS: Linux (Any), UNIX (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 1 Jul 2008 23:38:30 -0400
Subject: GraphicsMagick
|
http://sourceforge.net/project/shownotes.php?release_id=610253
1.2.4 (June 29, 2008)
====================
Security Fixes:
* AVI reader: Re-worked to be more robust against crash or DOS.
* AVS reader: Re-worked to be more robust against crash or DOS.
* DCM reader: Re-worked to be more robust against crash or DOS.
* EPT reader: Re-worked to be more robust against crash or DOS.
* FITS reader: Re-worked to be more robust against crash or DOS.
* MTV reader: Re-worked to be more robust against crash or DOS.
* PALM reader: Re-worked to be more robust against crash or DOS.
* RLA reader: Re-worked to be more robust against crash or DOS.
* TGA reader: Re-worked to be more robust against crash or DOS.
* Avoid possible crash in GetImageCharacteristics() when substituting
text in comment read from file.
|
|