USN-3363-2: ImageMagick regression
Vendor
Canonical Ubuntu
Versions Affected
- Canonical Ubuntu 14.04
Description
USN-3363-1 fixed vulnerabilities in ImageMagick. The update caused a regression for certain users when processing images. The problematic patch has been reverted pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privileges of the user invoking the program.
Affected Cloud Foundry Products and Versions
- All versions of Cloud Foundry cflinuxfs2 prior to 1.145.0
Mitigation
OSS users are strongly encouraged to follow one of the mitigations below:
- The Cloud Foundry project recommends that Cloud Foundry deployments run with cflinuxfs2 version 1.145.0 or later.