GLSA-200503-11 : ImageMagick: Filename handling vulnerability
High Nessus Plugin ID 17283
SynopsisThe remote Gentoo host is missing one or more security-related patches.
DescriptionThe remote host is affected by the vulnerability described in GLSA-200503-11 (ImageMagick: Filename handling vulnerability)
Tavis Ormandy of the Gentoo Linux Security Audit Team has identified a flaw in the handling of filenames by the ImageMagick utilities.
Successful exploitation may disrupt web applications that depend on ImageMagick for image processing, potentially executing arbitrary code.
There is no known workaround at this time.
SolutionAll ImageMagick users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=media-gfx/imagemagick-188.8.131.52'