[SECURITY] Fedora Core 4 Update: ImageMagick-6.2.2.0-3.fc4.2

Matthias Clasen mclasen at redhat.com
Wed May 24 23:37:27 UTC 2006


---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2006-587
2006-05-24
---------------------------------------------------------------------

Product     : Fedora Core 4
Name        : ImageMagick
Version     : 6.2.2.0                      
Release     : 3.fc4.2                  
Summary     : An X application for displaying and manipulating images.
Description :
ImageMagick(TM) is an image display and manipulation tool for the X
Window System. ImageMagick can read and write JPEG, TIFF, PNM, GIF,
and Photo CD image formats. It can resize, rotate, sharpen, color
reduce, or add special effects to an image, and when finished you can
either save the completed work in the original format or a different
one. ImageMagick also includes command line programs for creating
animated or transparent .gifs, creating composite images, creating
thumbnail images, and more.

ImageMagick is one of your choices if you need a program to manipulate
and dis play images. If you want to develop your own applications
which use ImageMagick code or APIs, you need to install
ImageMagick-devel as well.

---------------------------------------------------------------------
Update Information:

ImageMagick's DisplayImageCommand contains a heap 
overflow flaw.  It is possible to pass an unexpanded
glob to ImageMagick which will be expanded by
ImageMagick and overflow heap memory.

The updated package fixes this problem.
---------------------------------------------------------------------
* Wed May 24 2006 Matthias Clasen <mclasen at redhat.com> - 6.2.2.0-3.fc4.2
- Fix a heap overflow CVE-2006-2440 (#192279)

---------------------------------------------------------------------
This update can be downloaded from:
  http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/

880aa3ef59502bf1bd0133cf77c7b88fa984c5b7  SRPMS/ImageMagick-6.2.2.0-3.fc4.2.src.rpm
b295936ce3884b6ad5a15004f380379d361c9d2a  ppc/ImageMagick-6.2.2.0-3.fc4.2.ppc.rpm
1af9f800aa0841938a415a40f563b5bc7bbfac0c  ppc/ImageMagick-devel-6.2.2.0-3.fc4.2.ppc.rpm
b64ee36d3fe5ebea1e5bfbf1f174c92d22ae60d9  ppc/ImageMagick-perl-6.2.2.0-3.fc4.2.ppc.rpm
fec3fae448b83c9f78fdac69fe60f375a60abd60  ppc/ImageMagick-c++-6.2.2.0-3.fc4.2.ppc.rpm
51f5e4a391d487542e8f9cedb62ac4584c1c1555  ppc/ImageMagick-c++-devel-6.2.2.0-3.fc4.2.ppc.rpm
98c7b4ef9cf86e9bca32dc1f8f503df56b5a0150  ppc/debug/ImageMagick-debuginfo-6.2.2.0-3.fc4.2.ppc.rpm
78b4235d146248facc3ada00838fae69eaf794ba  ppc/ImageMagick-6.2.2.0-3.fc4.2.ppc64.rpm
923cfe47a1934e9aa6e7843b291827aeffa2578a  ppc/ImageMagick-c++-6.2.2.0-3.fc4.2.ppc64.rpm
b35325128370341ae59f0107edadee5c40c6337d  x86_64/ImageMagick-6.2.2.0-3.fc4.2.x86_64.rpm
16480bdc2c157d25686e84ad4f801071fee1a622  x86_64/ImageMagick-devel-6.2.2.0-3.fc4.2.x86_64.rpm
a240660e9dffc5595f51020a3a0df51b1e653e2d  x86_64/ImageMagick-perl-6.2.2.0-3.fc4.2.x86_64.rpm
3c98e3293ad9d0a6df29aaeb4e053beb6c188469  x86_64/ImageMagick-c++-6.2.2.0-3.fc4.2.x86_64.rpm
5de2a74e746933e0832c6064c26064618964a8fa  x86_64/ImageMagick-c++-devel-6.2.2.0-3.fc4.2.x86_64.rpm
6a26dc911c61ac368c3f09a7cea3e8145115e7cf  x86_64/debug/ImageMagick-debuginfo-6.2.2.0-3.fc4.2.x86_64.rpm
a25f53737b62d7081746efdcf88ce2565d6c1b13  i386/ImageMagick-6.2.2.0-3.fc4.2.i386.rpm
8eb1983d6c444ce9f931124564cc417eb7f04a3a  i386/ImageMagick-devel-6.2.2.0-3.fc4.2.i386.rpm
66ad32658841da1039787b9bb399b2061efd618e  i386/ImageMagick-perl-6.2.2.0-3.fc4.2.i386.rpm
85d46fff4242e6434727cd1e3ac562c8d4a36c7a  i386/ImageMagick-c++-6.2.2.0-3.fc4.2.i386.rpm
9dc70e8f20d3d393d7d1a0627a6387f1b2f75e54  i386/ImageMagick-c++-devel-6.2.2.0-3.fc4.2.i386.rpm
39b482b2e8e8864281d87442c9a6850342c18fe5  i386/debug/ImageMagick-debuginfo-6.2.2.0-3.fc4.2.i386.rpm

This update can be installed with the 'yum' update program.  Use 'yum update
package-name' at the command line.  For more information, refer to 'Managing
Software with yum,' available at http://fedora.redhat.com/docs/yum/.
---------------------------------------------------------------------




More information about the package-announce mailing list