Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-17618

Опубликовано: 05 июн. 2026
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2026-17618: ImageMagick security update (MODERATE)

[6.9.10.68-7.0.11]

  • Fix CVE-2026-32636 [Orabug: 39375225]

[6.9.10.68-7.0.9]

  • Fix CVE-2026-28691 and CVE-2026-28693 [Orabug: 39174244]

[6.9.10.68-7.0.7]

  • Fixes Local File Disclosure via Path Traversal (CVE-2026-25965) [Orabug: 39118995]
  • Fixes Memory allocation with excessive without limits in the internal SVG decoder (CVE-2026-25985)

[6.9.10.68-7.0.5]

  • Fix CVE-2025-62171 and CVE-2026-23876 [Orabug: 38997140]

[6.9.10.68-7.0.3]

  • Security update CVE-2025-57803 [Orabug: 38455460]

[6.9.10.68-7.0.1]

  • Fix for CVE-2025-55154 [Orabug: 38417011]

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

ImageMagick

6.9.10.68-7.0.11.el7_9

ImageMagick-c++

6.9.10.68-7.0.11.el7_9

ImageMagick-c++-devel

6.9.10.68-7.0.11.el7_9

ImageMagick-devel

6.9.10.68-7.0.11.el7_9

ImageMagick-doc

6.9.10.68-7.0.11.el7_9

ImageMagick-perl

6.9.10.68-7.0.11.el7_9

Связанные CVE

Связанные уязвимости

CVSS3: 5.3
ubuntu
5 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. Versions 7.1.2-17 and 6.9.13-42 fix the issue.

CVSS3: 7.5
redhat
5 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. Versions 7.1.2-17 and 6.9.13-42 fix the issue.

CVSS3: 5.3
nvd
5 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. Versions 7.1.2-17 and 6.9.13-42 fix the issue.

CVSS3: 5.3
debian
5 месяцев назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 5.3
github
5 месяцев назад

ImageMagick has a heap-buffer-overflow in NewXMLTree which could result in crash