Contact | Site en Français               

 


 

Vulnerabilities & Threats

 
  VUPEN Security Advisories
  Linux Security Advisories

  Malware Advisories

  Security Research
  Threat Watch Blog
  Zero-Day Monitor
  Search Engine
  Mailing List & RSS
 
   

>> Fedora Security Update Fixes GraphicsMagick Code Execution Vulnerabilities

Title : Fedora Security Update Fixes GraphicsMagick Code Execution Vulnerabilities
VUPEN ID : VUPEN/ADV-2007-2711
CVE ID : CVE-2005-4601 - CVE-2006-0082 - CVE-2006-4144 - CVE-2006-5456 - CVE-2007-1797
Rated as : High Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2007-07-31


Technical Description    Receive VUPEN Security alerts in a Text format  Receive VUPEN Security alerts in a PDF format  Receive VUPEN Security alerts in an XML format  Receive VUPEN Security notifications by SMS 

Multiple vulnerabilities have been identified in Fedora, which could be exploited by attackers to execute arbitrary code or cause a denial of service. These issues are caused by errors in GraphicsMagick. For additional information, see : VUPEN/ADV-2006-0333 - VUPEN/ADV-2006-4170 - VUPEN/ADV-2007-1200 - VUPEN/ADV-2006-3279

Affected Products

Fedora 7

Solution

Upgrade the affected packages :

ad121f81498ba231ea300e957a3b0b315ea42919 GraphicsMagick-1.1.8-2.fc7.ppc64.rpm
99bd8446f31914ed021c38a4d5c4cc18794acdb2 GraphicsMagick-devel-1.1.8-2.fc7.ppc64.rpm
82854218d401f3b209f2fe41eb5a5182ea432550 GraphicsMagick-debuginfo-1.1.8-2.fc7.ppc64.rpm
ffc23fbc0431b0b248362496a622d58fc43b70c5 GraphicsMagick-perl-1.1.8-2.fc7.ppc64.rpm
078ae1b20dd9874dde33bf11742c34e17e4b4027 GraphicsMagick-c++-1.1.8-2.fc7.ppc64.rpm
311bdec4431013f766c0e28382ecf23d370a3b7f GraphicsMagick-c++-devel-1.1.8-2.fc7.ppc64.rpm
0b2eb3f9fc0bc606381e9b78165c876ab75bf59a GraphicsMagick-1.1.8-2.fc7.i386.rpm
22f123c7349e302ce6d4db510a1736401f341aaa GraphicsMagick-c++-1.1.8-2.fc7.i386.rpm
747c808485858a11444625558e6278a1413387b2 GraphicsMagick-perl-1.1.8-2.fc7.i386.rpm
5303008ccb26b70c89b349078fbd41357a73b314 GraphicsMagick-c++-devel-1.1.8-2.fc7.i386.rpm
7e8320f08b2d430cd94dda42e87a59ac43499075 GraphicsMagick-devel-1.1.8-2.fc7.i386.rpm
0f2d97cd5adf03c6b5431f4bdf4a2879616f91f9 GraphicsMagick-debuginfo-1.1.8-2.fc7.i386.rpm
fa4753e3906ba9d8379fb5817f9b66e45c68f6ec GraphicsMagick-debuginfo-1.1.8-2.fc7.x86_64.rpm
e5fb588ad48b49b24609aaaaa399ba6e5e3153b5 GraphicsMagick-devel-1.1.8-2.fc7.x86_64.rpm
7496b323c15608a224ee738dd3eef32ff3639819 GraphicsMagick-perl-1.1.8-2.fc7.x86_64.rpm
04cb5db0bcd3e17b0b0a8c2e81b6e4a5d0495c30 GraphicsMagick-c++-1.1.8-2.fc7.x86_64.rpm
0db91845e5d6fed1becfe71adbe48d60eefc1c7e GraphicsMagick-1.1.8-2.fc7.x86_64.rpm
d35a35387aaf10f5c8d7fc1e013bbc26bd291584 GraphicsMagick-c++-devel-1.1.8-2.fc7.x86_64.rpm
335b374e273bdf5181634c1426d26e6eb71be1fe GraphicsMagick-debuginfo-1.1.8-2.fc7.ppc.rpm
7397c86594e57445a6d0efe2e92b99819517f7b0 GraphicsMagick-c++-1.1.8-2.fc7.ppc.rpm
d2dbc7d865c9e01c597a66855a88ed6c57c27e65 GraphicsMagick-c++-devel-1.1.8-2.fc7.ppc.rpm
3c1290e9a19c349f05a7442476a2a443997bb838 GraphicsMagick-perl-1.1.8-2.fc7.ppc.rpm
4509e52936d938cede2eea8305fcaeecc33359ff GraphicsMagick-devel-1.1.8-2.fc7.ppc.rpm
ca6f45a5a9a472f38f1a3b40d256cd8df67aaaa4 GraphicsMagick-1.1.8-2.fc7.ppc.rpm
c1ce1b43c6aa7efe7f3b851cabdfccd242f3eae7 GraphicsMagick-1.1.8-2.fc7.src.rpm

References

http://www.vupen.com/english/advisories/2007/2711
https://www.redhat.com/archives/fedora-package-announce/2007-July/msg00526.html

ChangeLog

2007-07-31 : Initial release

Vulnerability Management

Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form.

 

Vulnerability Alerting

Free 14-Day Trial

 
  Latest News

 

  >> 2009-06-10

     

  VUPEN Security Research
  Discovered Critical Flaws
  in Adobe Acrobat and MS

  Office Word


  >> 2009-06-02

     

  VUPEN Security Research
  Discovered Critical Flaws
  in ACDSee Products


  >> 2009-05-22

     

  VUPEN Discovered Two
  Critical Vulnerabilities in
  Novell GroupWise 8 / 7


  >> 2009-05-12

     

  Microsoft Patched 14
  Office PowerPoint Flaws

 

  >> 2009-04-28

     

  Adobe Reader / Acrobat
  Vulnerabilities
Disclosed

 

 

More Informations    
    








Copyright 2003-2009 © VUPEN.COM - Privacy Policy