Tavis Ormandy, Google Security Team, told us about several integer and buffer overflow flaws in ImageMagick. These flaws are present in ImageMagick's sun bitmap decoder and the xcf decoder.
These issues also affect RHEL2 and RHEL3
Created attachment 134022 [details] Proposed patch from Tavis
I have created a RHTS testcase with the demo images, and I have built ImageMagick-5.3.8-15 (RHEL2.1) ImageMagick-5.5.6-19 (RHEL3) ImageMagick-6.0.7.1-15 (RHEL4) with the fix. Note that I had no chance to verify the testcase or test the fix yet, since RHTS is down.
This errata will be RHSA-2006:0633
An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2006-0633.html