USN-4192-1: ImageMagick vulnerabilities
Severity
Medium
Vendor
Canonical Ubuntu
Versions Affected
- Canonical Ubuntu 18.04
 
Description
It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privileges of the user invoking the program.
CVEs contained in this USN include: CVE-2019-12974, CVE-2019-12975, CVE-2019-12976, CVE-2019-12977, CVE-2019-12978, CVE-2019-12979, CVE-2019-13135, CVE-2019-13137, CVE-2019-13295, CVE-2019-13297, CVE-2019-13300, CVE-2019-13301, CVE-2019-13304, CVE-2019-13305, CVE-2019-13306, CVE-2019-13307, CVE-2019-13308, CVE-2019-13309, CVE-2019-13310, CVE-2019-13311, CVE-2019-13391, CVE-2019-13454, CVE-2019-14981, CVE-2019-15139, CVE-2019-15140, CVE-2019-16708, CVE-2019-16709, CVE-2019-16710, CVE-2019-16711, CVE-2019-16713
Affected Cloud Foundry Products and Versions
Severity is medium unless otherwise noted.
- All versions of Cloud Foundry cflinuxfs3 prior to 0.144.0
 
Mitigation
Users of affected products are strongly encouraged to follow one of the mitigations below:
- The Cloud Foundry project recommends that Cloud Foundry deployments run with cflinuxfs3 version 0.144.0 or later.
 
References
- USN-4192-1
 - CVE-2019-12974
 - CVE-2019-12975
 - CVE-2019-12976
 - CVE-2019-12977
 - CVE-2019-12978
 - CVE-2019-12979
 - CVE-2019-13135
 - CVE-2019-13137
 - CVE-2019-13295
 - CVE-2019-13297
 - CVE-2019-13300
 - CVE-2019-13301
 - CVE-2019-13304
 - CVE-2019-13305
 - CVE-2019-13306
 - CVE-2019-13307
 - CVE-2019-13308
 - CVE-2019-13309
 - CVE-2019-13310
 - CVE-2019-13311
 - CVE-2019-13391
 - CVE-2019-13454
 - CVE-2019-14981
 - CVE-2019-15139
 - CVE-2019-15140
 - CVE-2019-16708
 - CVE-2019-16709
 - CVE-2019-16710
 - CVE-2019-16711
 - CVE-2019-16713
 
    