Debian セキュリティ勧告

DSA-957-2 imagemagick -- シェルメタ文字のサニタイズ欠落

報告日時:
2006-01-26
影響を受けるパッケージ:
imagemagick
危険性:
あり
参考セキュリティデータベース:
Debian バグ追跡システム: バグ 345238.
(SecurityFocus の) Bugtraq データベース: BugTraq ID 16093.
Mitre の CVE 辞書: CVE-2005-4601.
詳細:

Florian Weimer さんが、ImageMagick の delegate のコードが、 特別に細工したファイル名を使用したシェルコマンドの差し込みに対して脆弱であることを発見しました。 これにより、攻撃者に graphic コマンド内部でのコマンド展開を許します。 ユーザによる操作をいくらか伴うことで、Gnus と Thunderbird から悪用可能です。 この更新により、以前の更新で忘れられていた「$」文字についても捕捉します。

旧安定版 (old stable) ディストリビューション (woody) では、この問題はバージョン 5.4.4.5-1woody8 で修正されています。

安定版 (stable) ディストリビューション (sarge) では、この問題はバージョン 6.0.6.2-2.6 で修正されています。

不安定版 (unstable) ディストリビューション (sid) では、この問題はバージョン 6.2.4.5-0.6 で修正されています。

直ちに imagemagick パッケージをアップグレードすることを勧めます。

修正:

Debian GNU/Linux 3.0 (woody)

ソース:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_5.4.4.5-1woody8.dsc
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_5.4.4.5-1woody8.diff.gz
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_5.4.4.5.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_5.4.4.5-1woody8_alpha.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5_5.4.4.5-1woody8_alpha.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5-dev_5.4.4.5-1woody8_alpha.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5_5.4.4.5-1woody8_alpha.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5-dev_5.4.4.5-1woody8_alpha.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_5.4.4.5-1woody8_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_5.4.4.5-1woody8_arm.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5_5.4.4.5-1woody8_arm.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5-dev_5.4.4.5-1woody8_arm.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5_5.4.4.5-1woody8_arm.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5-dev_5.4.4.5-1woody8_arm.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_5.4.4.5-1woody8_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_5.4.4.5-1woody8_i386.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5_5.4.4.5-1woody8_i386.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5-dev_5.4.4.5-1woody8_i386.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5_5.4.4.5-1woody8_i386.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5-dev_5.4.4.5-1woody8_i386.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_5.4.4.5-1woody8_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_5.4.4.5-1woody8_ia64.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5_5.4.4.5-1woody8_ia64.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5-dev_5.4.4.5-1woody8_ia64.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5_5.4.4.5-1woody8_ia64.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5-dev_5.4.4.5-1woody8_ia64.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_5.4.4.5-1woody8_ia64.deb
HPPA:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_5.4.4.5-1woody8_hppa.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5_5.4.4.5-1woody8_hppa.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5-dev_5.4.4.5-1woody8_hppa.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5_5.4.4.5-1woody8_hppa.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5-dev_5.4.4.5-1woody8_hppa.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_5.4.4.5-1woody8_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_5.4.4.5-1woody8_m68k.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5_5.4.4.5-1woody8_m68k.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5-dev_5.4.4.5-1woody8_m68k.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5_5.4.4.5-1woody8_m68k.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5-dev_5.4.4.5-1woody8_m68k.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_5.4.4.5-1woody8_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_5.4.4.5-1woody8_mips.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5_5.4.4.5-1woody8_mips.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5-dev_5.4.4.5-1woody8_mips.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5_5.4.4.5-1woody8_mips.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5-dev_5.4.4.5-1woody8_mips.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_5.4.4.5-1woody8_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_5.4.4.5-1woody8_mipsel.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5_5.4.4.5-1woody8_mipsel.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5-dev_5.4.4.5-1woody8_mipsel.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5_5.4.4.5-1woody8_mipsel.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5-dev_5.4.4.5-1woody8_mipsel.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_5.4.4.5-1woody8_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_5.4.4.5-1woody8_powerpc.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5_5.4.4.5-1woody8_powerpc.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5-dev_5.4.4.5-1woody8_powerpc.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5_5.4.4.5-1woody8_powerpc.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5-dev_5.4.4.5-1woody8_powerpc.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_5.4.4.5-1woody8_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_5.4.4.5-1woody8_s390.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5_5.4.4.5-1woody8_s390.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5-dev_5.4.4.5-1woody8_s390.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5_5.4.4.5-1woody8_s390.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5-dev_5.4.4.5-1woody8_s390.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_5.4.4.5-1woody8_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_5.4.4.5-1woody8_sparc.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5_5.4.4.5-1woody8_sparc.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++5-dev_5.4.4.5-1woody8_sparc.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5_5.4.4.5-1woody8_sparc.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick5-dev_5.4.4.5-1woody8_sparc.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_5.4.4.5-1woody8_sparc.deb

Debian GNU/Linux 3.1 (sarge)

ソース:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_6.0.6.2-2.6.dsc
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_6.0.6.2-2.6.diff.gz
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_6.0.6.2.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_6.0.6.2-2.6_alpha.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6_6.0.6.2-2.6_alpha.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6-dev_6.0.6.2-2.6_alpha.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6_6.0.6.2-2.6_alpha.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6-dev_6.0.6.2-2.6_alpha.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_6.0.6.2-2.6_alpha.deb
AMD64:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_6.0.6.2-2.6_amd64.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6_6.0.6.2-2.6_amd64.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6-dev_6.0.6.2-2.6_amd64.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6_6.0.6.2-2.6_amd64.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6-dev_6.0.6.2-2.6_amd64.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_6.0.6.2-2.6_amd64.deb
ARM:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_6.0.6.2-2.6_arm.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6_6.0.6.2-2.6_arm.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6-dev_6.0.6.2-2.6_arm.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6_6.0.6.2-2.6_arm.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6-dev_6.0.6.2-2.6_arm.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_6.0.6.2-2.6_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_6.0.6.2-2.6_i386.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6_6.0.6.2-2.6_i386.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6-dev_6.0.6.2-2.6_i386.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6_6.0.6.2-2.6_i386.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6-dev_6.0.6.2-2.6_i386.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_6.0.6.2-2.6_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_6.0.6.2-2.6_ia64.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6_6.0.6.2-2.6_ia64.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6-dev_6.0.6.2-2.6_ia64.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6_6.0.6.2-2.6_ia64.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6-dev_6.0.6.2-2.6_ia64.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_6.0.6.2-2.6_ia64.deb
HPPA:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_6.0.6.2-2.6_hppa.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6_6.0.6.2-2.6_hppa.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6-dev_6.0.6.2-2.6_hppa.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6_6.0.6.2-2.6_hppa.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6-dev_6.0.6.2-2.6_hppa.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_6.0.6.2-2.6_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_6.0.6.2-2.6_m68k.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6_6.0.6.2-2.6_m68k.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6-dev_6.0.6.2-2.6_m68k.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6_6.0.6.2-2.6_m68k.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6-dev_6.0.6.2-2.6_m68k.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_6.0.6.2-2.6_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_6.0.6.2-2.6_mips.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6_6.0.6.2-2.6_mips.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6-dev_6.0.6.2-2.6_mips.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6_6.0.6.2-2.6_mips.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6-dev_6.0.6.2-2.6_mips.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_6.0.6.2-2.6_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_6.0.6.2-2.6_mipsel.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6_6.0.6.2-2.6_mipsel.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6-dev_6.0.6.2-2.6_mipsel.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6_6.0.6.2-2.6_mipsel.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6-dev_6.0.6.2-2.6_mipsel.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_6.0.6.2-2.6_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_6.0.6.2-2.6_powerpc.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6_6.0.6.2-2.6_powerpc.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6-dev_6.0.6.2-2.6_powerpc.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6_6.0.6.2-2.6_powerpc.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6-dev_6.0.6.2-2.6_powerpc.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_6.0.6.2-2.6_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_6.0.6.2-2.6_s390.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6_6.0.6.2-2.6_s390.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6-dev_6.0.6.2-2.6_s390.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6_6.0.6.2-2.6_s390.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6-dev_6.0.6.2-2.6_s390.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_6.0.6.2-2.6_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/i/imagemagick/imagemagick_6.0.6.2-2.6_sparc.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6_6.0.6.2-2.6_sparc.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick++6-dev_6.0.6.2-2.6_sparc.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6_6.0.6.2-2.6_sparc.deb
http://security.debian.org/pool/updates/main/i/imagemagick/libmagick6-dev_6.0.6.2-2.6_sparc.deb
http://security.debian.org/pool/updates/main/i/imagemagick/perlmagick_6.0.6.2-2.6_sparc.deb

一覧にあるファイルの MD5 チェックサムは勧告の原文にあります。

一覧にあるファイルの MD5 チェックサムは勧告の原文 (改訂版) にあります。