USN-3142-2: ImageMagick regression
Severity
Medium
Vendor
Canonical Ubuntu
Versions Affected
- Canonical Ubuntu 14.04 LTS
Description
USN-3142-1 fixed vulnerabilities in ImageMagick. The security fixes introduced a regression with text labels and a regression with the textcoder. This update fixes the problem.
It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privileges of the user invoking the program.
Affected Cloud Foundry Products and Versions
Severity is medium unless otherwise noted.
- cflinuxfs2 prior to v1.103.0
Mitigation
The Cloud Foundry project recommends that Cloud Foundry deployments run with cflinuxfs2 v1.103.0 or later versions.