Skip to content

emka.web.id

Banner 1
Menu
  • Home
  • Indeks Artikel
  • Tutorial
  • Tentang Kami
Menu

Linux News Today: Canonical Patches ImageTragick Exploit in All Supported Ubuntu OSes, Update Now

Posted on June 02, 2016 by Syauqi Wiryahasana

Today, June 2, 2016, Canonical published an Ubuntu Security Notice to inform the community about an important security update to the ImageMagick packages for all supported Ubuntu OSes.

According to Ubuntu Security Notice USN-2990-1, there are two ImageMagick vulnerabilities affecting the Ubuntu 16.04 LTS (Xenial Xerus), Ubuntu 15.10 (Wily Werewolf), Ubuntu 14.04 LTS (Trusty Tahr), and Ubuntu 12.04 LTS (Precise Pangolin) operating systems, as well as all of their derivatives.

ImageMagick is an open-source image manipulation library that contains a set of commands which users can use to resize, crop, edit, compose, or convert various types of images. However, ImageMagick can also be easily integrated into various imaged editor programs.

Today's update is very important as it patched the infamous "ImageTragick" exploit discovered a month ago by Nikolay Ermishkin and Stewie in the upstream ImageMagick packages, which failed to correctly sanitize untrusted input, thus allowing remote attackers to execute arbitrary code on the affected system.

"This update disables problematic coders via the /etc/ImageMagick-6/policy.xml configuration file. In certain environments the coders may need to be manually re-enabled after making sure that ImageMagick does not process untrusted input," reads Canonical's latest security notice for ImageMagick.

The second ImageMagick vulnerability patched in today's update for Ubuntu Linux operating systems is a security issue discovered by Bob Friesenhahn in ImageMagick, which could allow remote attackers to run malicious code on the affected system by injecting commands via either an image file or filename.

All Ubuntu users need to update their systems as soon as possible

Therefore, if you are using one of the supported Ubuntu releases, Canonical recommends that you install the latest updates from the main software repositories using either the command-line APT package manager or the Ubuntu Software GUI, as soon as possible. The patched ImageMagick versions are now live.

The new ImageMagick versions are libmagick++-6.q16-5v5 8:6.8.9.9-7ubuntu5.1 for Ubuntu 16.04 LTS, libmagick++-6.q16-5v5 8:6.8.9.9-5ubuntu2.1 for Ubuntu 15.10, libmagick++5 8:6.7.7.10-6ubuntu3.1 for Ubuntu 14.04 LTS, and imagemagick-common 8:6.6.9.7-5ubuntu3.4 for Ubuntu 12.04 LTS.

Via Softpedia
Banner 1
Seedbacklink

Recent Posts

  • AS dan Arab Saudi Deal Jual-Beli Senjata 142 Miliar Dollar
  • Sejarah Injil Thomas dan Kristen Gnostik yang Terlarang
  • Sejarah Mufti Palestina Berkoalisi dengan NAZI Jerman
  • Trik Licik Bandar Judi Online yang Kamu Belum Tahu
  • Misteri DNA Nenek Moyang Manusia Mexico
  • Sejarah Peradaban Tartessos
  • Benarkah Badai Matahari Picu Gempa 8 Skala Richter Atau Lebih?
  • Sejarah Harley-Davidson Jadi Kultus Tato Terbanyak di Dunia
  • Guru Gembul: Pacaran Menurut Sains Itu Baik?
  • G30S Jadi Revolusi Gagal atau Memang Rencana Soeharto?
  • Film Jumbo 9,2 Juta Penonton: Faktor Fluke Effect, Apa itu?
  • Sejarah Wahana Tianwen-1 China Mendarat di Mars
  • Pengertian dan Sejarah Mesin Linotype (Mesin Cetak Baris)
  • Apa itu Negara Mikronesia? Tetangga Rese Indonesia?
  • Apa itu Virus Tumbuhan (Plant Virus)?
  • Nio Perkenalkan Mobil Listrik ES6, EC6, ET5 dan ET5T
  • Mobil Prototipe Huawei Stelato S9 Kena Foto Netizen Lagi, Lebih Canggih?
  • Honda Dihajar BYD Di Indonesia, Turun Parah di April 2025
  • Konami Adakan Event Ulang Tahun ke 8 eFootball Mobile
  • Apa Itu RUU Keamanan dan Ketahanan Siber (RUU KKS)?
  • Pabrik Prosesor China Hygon Kini Buat CPU Server 128 Core
  • Standard Chartered: Mimpi Bitcoin 120 Ribu Dollar itu Terlalu Rendah
  • Palantir Masuk Top 10 Perusahaan Amerika, Kenapa?
  • Puji Tuhan, Paus Leo XIV Disahkan Jadi Paus Pertama dari Amerika
  • Ubuntu 25.10 Akan Pakai Sudo Baru dari Bahasa Rust

TENTANG EMKA.WEB>ID

EMKA.WEB.ID adalah blog seputar teknologi informasi, edukasi dan ke-NU-an yang hadir sejak tahun 2011. Kontak: kontak@emka.web.id.

©2024 emka.web.id Proudly powered by wpStatically