Submitted by KeesCook on Tue, 2007-07-10 13:32
Referenced CVEs:
CVE-2007-1667, CVE-2007-1797
Description:
===========================================================
Ubuntu Security Notice USN-481-1 July 10, 2007
imagemagick vulnerabilities
CVE-2007-1667, CVE-2007-1797
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libmagick9 6:6.2.4.5-0.6ubuntu0.6
Ubuntu 6.10:
libmagick9 7:6.2.4.5.dfsg1-0.10ubuntu0.3
Ubuntu 7.04:
libmagick9 7:6.2.4.5.dfsg1-0.14ubuntu0.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Multiple vulnerabilities were found in ImageMagick's handling of DCM and
WXD image files. By tricking a user into processing a specially crafted
image with an application that uses imagemagick, an attacker could
execute arbitrary code with the user's privileges.


