[Technik] [SECURITY] [DSA 1260-1] New imagemagick package fix
arbitrary code execution
Noèl Köthe
noel at debian.org
Thu Feb 15 08:33:11 CET 2007
Am Mittwoch, den 14.02.2007, 22:04 +0100 schrieb Moritz Muehlenhoff:
> Debian Security Advisory DSA 1260-1 security at debian.org
> http://www.debian.org/security/ Moritz Muehlenhoff
> February 14th, 2007 http://www.debian.org/security/faq
>
> Package : imagemagick
> Vulnerability : buffer overflow
> Problem-Type : local(remote)
> Debian-specific: no
> CVE ID : CVE-2007-0770
imagemagick auf h01, h02, h03, h04 und h90 aktualisiert.
> For the stable distribution (sarge) this problem has been fixed in
> version 6:6.0.6.2-2.9.
imagemagick (6:6.0.6.2-2.9) stable-security; urgency=high
* Non-maintainer upload for the Security Team.
* coders/palm.c: Fix regression introduced in patch for CVE-2006-5456.
Avoid bogus second read in macro call. Patch thanks to Vladimir
Nadvornik. (CVE-2007-0770)
-- Daniel Kobras <kobras at debian.org> Sat, 10 Feb 2007 15:59:32 +0100
--
Noèl Köthe <noel debian.org>
Debian GNU/Linux, www.debian.org
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Dies ist ein digital signierter Nachrichtenteil
Url : /archiv/technik/attachments/20070215/c851622b/attachment.pgp
More information about the Technik
mailing list