Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:0540-1

Опубликовано: 21 фев. 2022
Источник: suse-cvrf

Описание

Security update for ImageMagick

This update for ImageMagick fixes the following issues:

  • CVE-2022-0284: Fixed heap buffer overread in GetPixelAlpha() in MagickCore/pixel-accessor.h (bsc#1195563).

Список пакетов

SUSE Linux Enterprise Module for Desktop Applications 15 SP3
ImageMagick-7.0.7.34-10.21.1
ImageMagick-config-7-SUSE-7.0.7.34-10.21.1
ImageMagick-config-7-upstream-7.0.7.34-10.21.1
ImageMagick-devel-7.0.7.34-10.21.1
libMagick++-7_Q16HDRI4-7.0.7.34-10.21.1
libMagick++-devel-7.0.7.34-10.21.1
libMagickCore-7_Q16HDRI6-7.0.7.34-10.21.1
libMagickWand-7_Q16HDRI6-7.0.7.34-10.21.1
SUSE Linux Enterprise Module for Development Tools 15 SP3
perl-PerlMagick-7.0.7.34-10.21.1
SUSE Linux Enterprise Real Time 15 SP2
ImageMagick-7.0.7.34-10.21.1
ImageMagick-config-7-SUSE-7.0.7.34-10.21.1
ImageMagick-config-7-upstream-7.0.7.34-10.21.1
ImageMagick-devel-7.0.7.34-10.21.1
libMagick++-7_Q16HDRI4-7.0.7.34-10.21.1
libMagick++-devel-7.0.7.34-10.21.1
libMagickCore-7_Q16HDRI6-7.0.7.34-10.21.1
libMagickWand-7_Q16HDRI6-7.0.7.34-10.21.1
perl-PerlMagick-7.0.7.34-10.21.1

Описание

A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulnerability is triggered when an attacker passes a specially crafted Tagged Image File Format (TIFF) image to convert it into a PICON file format. This issue can potentially lead to a denial of service and information disclosure.


Затронутые продукты
SUSE Linux Enterprise Module for Desktop Applications 15 SP3:ImageMagick-7.0.7.34-10.21.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP3:ImageMagick-config-7-SUSE-7.0.7.34-10.21.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP3:ImageMagick-config-7-upstream-7.0.7.34-10.21.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP3:ImageMagick-devel-7.0.7.34-10.21.1

Ссылки