Описание
Security update for GraphicsMagick
This update for GraphicsMagick fixes the following issues:
- CVE-2026-26284: heap overflow in pcd decoder leads to out of bounds read (bsc#1258765).
- CVE-2026-28690: missing bounds check in the MNG encoder can lead to a stack buffer overflow (bsc#1259456).
Список пакетов
SUSE Linux Enterprise Module for Package Hub 15 SP7
Ссылки
- Link for SUSE-SU-2026:1300-1
- E-Mail link for SUSE-SU-2026:1300-1
- SUSE Security Ratings
- SUSE Bug 1258765
- SUSE Bug 1259456
- SUSE CVE CVE-2026-26284 page
- SUSE CVE CVE-2026-28690 page
Описание
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huffman-coded data from PCD (Photo CD) files. The decoder contains an function that has an incorrect initialization that could cause an out of bounds read. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Затронутые продукты
Ссылки
- CVE-2026-26284
- SUSE Bug 1258765
- SUSE Bug 1269891
Описание
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow vulnerability exists in the MNG encoder. There is a bounds checks missing that could corrupting the stack with attacker-controlled data. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Затронутые продукты
Ссылки
- CVE-2026-28690
- SUSE Bug 1259456