English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

ImageMagick Two Vulnerabilities


Secunia ID

SA47926

CVE-ID

CVE-2012-0247, CVE-2012-0248, CVE-2012-1185, CVE-2012-1186

Release Date

10 Feb 2012

Last Change

20 Mar 2012

Criticality

Moderately Critical

Solution Status

Vendor Patch

Software

ImageMagick 6.x

Where

From remote

Impact
DoS (Denial of Service)

This includes vulnerabilities ranging from excessive resource consumption (e.g. causing a system to use a lot of memory) to crashing an application or an entire system.

System access

This covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user.

Description

Two vulnerabilities have been reported in ImageMagick, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.

1) An error when parsing offset and count values within the ResolutionUnit tag in EXIF IFD0 can be exploited to corrupt memory via a specially crafted image.

Successful exploitation of this vulnerability may allow execution of arbitrary code.

2) An error when parsing an IFD with IOP tag offsets pointing to the start of the IFD can be exploited to cause an infinite loop via a specially crafted image.

The vulnerabilities are reported in versions prior to 6.7.5-8.

Solution

Update to version 6.7.5-8.

Reported by

The vendor credits Mr. Joonas Kuorilehto and Mr. Aleksis Kauppinen, Codenomicon CROSS project.

Original Advisory

http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20286