Referenced CVEs:
CVE-2009-1882
Description:
===========================================================Ubuntu Security Notice USN-784-1 June 09, 2009imagemagick vulnerabilityCVE-2009-1882===========================================================A security issue affects the following Ubuntu releases:Ubuntu 6.06 LTSUbuntu 8.04 LTSUbuntu 8.10Ubuntu 9.04This advisory also applies to the corresponding versions ofKubuntu, Edubuntu, and Xubuntu.The problem can be corrected by upgrading your system to thefollowing package versions:Ubuntu 6.06 LTS: libmagick9 6:6.2.4.5-0.6ubuntu0.9Ubuntu 8.04 LTS: libmagick10 7:6.3.7.9.dfsg1-2ubuntu1.1Ubuntu 8.10: libmagick10 7:6.3.7.9.dfsg1-2ubuntu3.1Ubuntu 9.04: libmagickcore1 7:6.4.5.4.dfsg1-1ubuntu3.1In general, a standard system upgrade is sufficient to effect thenecessary changes.Details follow:It was discovered that ImageMagick did not properly verify the dimensionsof TIFF files. If a user or automated system were tricked into opening acrafted TIFF file, an attacker could cause a denial of service or possiblyexecute arbitrary code with the privileges of the user invoking theprogram.
More...