DSA-2750-1 imagemagick -- buffer overflow

Related Vulnerabilities: CVE-2013-4298  

Anton Kortunov reported a heap corruption in ImageMagick, a program collection and library for converting and manipulating image files. Crafted GIF files could cause ImageMagick to crash, potentially leading to arbitrary code execution. The oldstable distribution (squeeze) is not affected by this problem. For the stable distribution (wheezy), this problem has been fixed in version 8:6.7.7.10-5+deb7u2. For the unstable distribution (sid), this problem has been fixed in version 8:6.7.7.10-6. We recommend that you upgrade your imagemagick packages.

Debian Security Advisory

DSA-2750-1 imagemagick -- buffer overflow

Date Reported:
03 Sep 2013
Affected Packages:
imagemagick
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 721273.
In Mitre's CVE dictionary: CVE-2013-4298.
More information:

Anton Kortunov reported a heap corruption in ImageMagick, a program collection and library for converting and manipulating image files. Crafted GIF files could cause ImageMagick to crash, potentially leading to arbitrary code execution.

The oldstable distribution (squeeze) is not affected by this problem.

For the stable distribution (wheezy), this problem has been fixed in version 8:6.7.7.10-5+deb7u2.

For the unstable distribution (sid), this problem has been fixed in version 8:6.7.7.10-6.

We recommend that you upgrade your imagemagick packages.