USN-6675-1: ImageProcessing vulnerability
5 March 2024
ImageProcessing could be made to crash or run programs as an administrator if it received specially crafted input.
Releases
Packages
- ruby-image-processing - High-level image processing wrapper for libvips and ImageMagick/GraphicsMagick
Details
It was discovered that ImageProcessing incorrectly handled series of operations
that are coming from unsanitised inputs. If a user or an automated system were
tricked into opening a specially crafted input file, a remote attacker could
possibly use this issue to execute arbitrary code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.04
Ubuntu 20.04
In general, a standard system update will make all the necessary changes.