Debian dla-3429 : imagemagick - security update

high Nessus Plugin ID 176199

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 10 host has packages installed that are affected by multiple vulnerabilities as referenced in the dla-3429 advisory.

- ------------------------------------------------------------------------- Debian LTS Advisory DLA-3429-1 [email protected] https://www.debian.org/lts/security/ Bastien Roucaries May 21, 2023 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : imagemagick Version : 8:6.9.10.23+dfsg-2.1+deb10u5 CVE ID : CVE-2021-20176 CVE-2021-20241 CVE-2021-20243 CVE-2021-20244 CVE-2021-20245 CVE-2021-20246 CVE-2021-20309 CVE-2021-20312 CVE-2021-20313 CVE-2021-39212 CVE-2022-28463 CVE-2022-32545 CVE-2022-32546 CVE-2022-32547 Debian Bug : 996588 1013282 1016442

Multiple vulnerabilities were fixed in imagemagick, a software suite, used for editing and manipulating digital images.

CVE-2021-20176

A divide by zero was found in gem.c file.

CVE-2021-20241

A divide by zero was found in jp2 coder.

CVE-2021-20243

A divide by zero was found in dcm coder.

CVE-2021-20244

A divide by zero was found in fx.c.

CVE-2021-20245

A divide by zero was found in webp coder.

CVE-2021-20246

A divide by zero was found in resample.c.

CVE-2021-20309

A divide by zero was found in WaveImage.c

CVE-2021-20312

An integer overflow was found in WriteTHUMBNAILImage() of coders/thumbnail.c

CVE-2021-20313

A potential cipher leak was found when the calculate signatures in TransformSignature().

CVE-2021-39212

A policy bypass was found for postscript files.

CVE-2022-28463

A bufer overflow was found in buffer overflow in cin coder.

CVE-2022-32545

A undefined behavior (conversion outside the range of representable values of type 'unsigned char') was found in psd file handling.

CVE-2022-32546

A undefined behavior (conversion outside the range of representable values of type 'long') was found in pcl file handling.

CVE-2022-32547

An unaligned access was found in property.c

For Debian 10 buster, these problems have been fixed in version 8:6.9.10.23+dfsg-2.1+deb10u5.

We recommend that you upgrade your imagemagick packages.

For the detailed security status of imagemagick please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/imagemagick

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the imagemagick packages.

See Also

https://security-tracker.debian.org/tracker/source-package/imagemagick

https://security-tracker.debian.org/tracker/CVE-2021-20176

https://security-tracker.debian.org/tracker/CVE-2021-20241

https://security-tracker.debian.org/tracker/CVE-2021-20243

https://security-tracker.debian.org/tracker/CVE-2021-20244

https://security-tracker.debian.org/tracker/CVE-2021-20245

https://security-tracker.debian.org/tracker/CVE-2021-20246

https://security-tracker.debian.org/tracker/CVE-2021-20309

https://security-tracker.debian.org/tracker/CVE-2021-20312

https://security-tracker.debian.org/tracker/CVE-2021-20313

https://security-tracker.debian.org/tracker/CVE-2021-39212

https://security-tracker.debian.org/tracker/CVE-2022-28463

https://security-tracker.debian.org/tracker/CVE-2022-32545

https://security-tracker.debian.org/tracker/CVE-2022-32546

https://security-tracker.debian.org/tracker/CVE-2022-32547

https://packages.debian.org/source/buster/imagemagick

Plugin Details

Severity: High

ID: 176199

File Name: debian_DLA-3429.nasl

Version: 1.2

Type: local

Agent: unix

Published: 5/22/2023

Updated: 1/22/2025

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2022-32547

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:imagemagick-doc, p-cpe:/a:debian:debian_linux:libmagickcore-6-headers, p-cpe:/a:debian:debian_linux:libmagickwand-6-headers, p-cpe:/a:debian:debian_linux:libmagickwand-6.q16hdri-dev, p-cpe:/a:debian:debian_linux:libmagickwand-6.q16hdri-6, p-cpe:/a:debian:debian_linux:libmagick%2b%2b-dev, p-cpe:/a:debian:debian_linux:imagemagick-6.q16hdri, p-cpe:/a:debian:debian_linux:libmagick%2b%2b-6.q16-8, p-cpe:/a:debian:debian_linux:libmagickcore-6.q16-6-extra, p-cpe:/a:debian:debian_linux:libmagickcore-dev, p-cpe:/a:debian:debian_linux:perlmagick, p-cpe:/a:debian:debian_linux:libmagickwand-6.q16-6, p-cpe:/a:debian:debian_linux:imagemagick, p-cpe:/a:debian:debian_linux:libmagickcore-6.q16hdri-6, p-cpe:/a:debian:debian_linux:libimage-magick-q16-perl, cpe:/o:debian:debian_linux:10.0, p-cpe:/a:debian:debian_linux:libmagickcore-6.q16hdri-6-extra, p-cpe:/a:debian:debian_linux:libmagickwand-dev, p-cpe:/a:debian:debian_linux:imagemagick-6-doc, p-cpe:/a:debian:debian_linux:libmagickwand-6.q16-dev, p-cpe:/a:debian:debian_linux:imagemagick-common, p-cpe:/a:debian:debian_linux:imagemagick-6-common, p-cpe:/a:debian:debian_linux:libmagick%2b%2b-6.q16hdri-8, p-cpe:/a:debian:debian_linux:libmagickcore-6.q16-dev, p-cpe:/a:debian:debian_linux:libmagickcore-6.q16-6, p-cpe:/a:debian:debian_linux:libimage-magick-q16hdri-perl, p-cpe:/a:debian:debian_linux:imagemagick-6.q16, p-cpe:/a:debian:debian_linux:libmagickcore-6.q16hdri-dev, p-cpe:/a:debian:debian_linux:libmagick%2b%2b-6.q16hdri-dev, p-cpe:/a:debian:debian_linux:libimage-magick-perl, p-cpe:/a:debian:debian_linux:libmagick%2b%2b-6-headers, p-cpe:/a:debian:debian_linux:libmagickcore-6-arch-config, p-cpe:/a:debian:debian_linux:libmagick%2b%2b-6.q16-dev

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/21/2023

Vulnerability Publication Date: 2/6/2021

Reference Information

CVE: CVE-2021-20176, CVE-2021-20241, CVE-2021-20243, CVE-2021-20244, CVE-2021-20245, CVE-2021-20246, CVE-2021-20309, CVE-2021-20312, CVE-2021-20313, CVE-2021-39212, CVE-2022-28463, CVE-2022-32545, CVE-2022-32546, CVE-2022-32547

IAVB: 2021-B-0017-S, 2022-B-0019-S, 2022-B-0032-S