Severity
Low
Vendor
Canonical Ubuntu
Versions Affected
- Canonical Ubuntu 18.04
Description
It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privileges of the user invoking the program.
CVEs contained in this USN include: CVE-2017-14528, CVE-2020-27757, CVE-2020-27771, CVE-2020-27763, CVE-2020-27758, CVE-2020-27754, CVE-2020-27776, CVE-2020-25674, CVE-2020-27770, CVE-2020-27773, CVE-2020-27750, CVE-2020-25665, CVE-2021-20176, CVE-2020-27765, CVE-2020-27774, CVE-2020-27775, CVE-2020-27751, CVE-2020-27764, CVE-2020-27769, CVE-2020-27767, CVE-2020-25666, CVE-2020-27755, CVE-2020-19667, CVE-2020-27768, CVE-2020-27772, CVE-2020-27761, CVE-2020-25675, CVE-2020-27760, CVE-2020-27762, CVE-2020-25676, CVE-2020-27753, CVE-2020-27766, CVE-2020-27759, CVE-2020-27756.
Affected Cloud Foundry Products and Versions
Severity is low unless otherwise noted.
- cflinuxfs3
- All versions prior to 0.243.0
- CF Deployment
- All versions prior to 16.16.0
Mitigation
Users of affected products are strongly encouraged to follow the mitigations below. The Cloud Foundry project recommends upgrading the following releases:
- cflinuxfs3
- Upgrade all versions to 0.243.0 or greater
- CF Deployment
- Upgrade all versions to 16.16.0 or greater
References
- USN Notice
- CVE-2017-14528
- CVE-2020-27757
- CVE-2020-27771
- CVE-2020-27763
- CVE-2020-27758
- CVE-2020-27754
- CVE-2020-27776
- CVE-2020-25674
- CVE-2020-27770
- CVE-2020-27773
- CVE-2020-27750
- CVE-2020-25665
- CVE-2021-20176
- CVE-2020-27765
- CVE-2020-27774
- CVE-2020-27775
- CVE-2020-27751
- CVE-2020-27764
- CVE-2020-27769
- CVE-2020-27767
- CVE-2020-25666
- CVE-2020-27755
- CVE-2020-19667
- CVE-2020-27768
- CVE-2020-27772
- CVE-2020-27761
- CVE-2020-25675
- CVE-2020-27760
- CVE-2020-27762
- CVE-2020-25676
- CVE-2020-27753
- CVE-2020-27766
- CVE-2020-27759
- CVE-2020-27756
History
2021-07-08: Initial vulnerability report published.