Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3023-1

Опубликовано: 15 июл. 2026
Источник: suse-cvrf

Описание

Security update for ImageMagick

This update for ImageMagick fixes the following issues

  • CVE-2026-42050: stack buffer overflow in XTileImage (bsc#1265048).
  • CVE-2026-42326: information disclosure via malicious IPTC input file (bsc#1268092).
  • CVE-2026-45031: denial of Service due to resource policy bypass in PSD decoder (bsc#1268094).
  • CVE-2026-45358: off by one in the meta encoder could result in an out of bounds read of a single byte in the meta encoder (bsc#1268102).
  • CVE-2026-45359: information Disclosure via Invalid Connected-Components Value (bsc#1268095).
  • CVE-2026-45624: data exposure due to image processing vulnerability (bsc#1268096).
  • CVE-2026-45664: denial of Service due to excessive resource use in MNG coder (bsc#1268101).
  • CVE-2026-46520: denial of Service via out-of-bounds write when processing multiple images (bsc#1268112).
  • CVE-2026-46521: out of bounds write can occur due to a missing check when using LZMA compression in the MIFF encoder (bsc#1268124).
  • CVE-2026-46522: denial of service via crafted MIFF file due to a missing check in the MIFF decoder (bsc#1268126).
  • CVE-2026-46523: heap-use-after-free via a crafted MSL image (bsc#1268125).
  • CVE-2026-46557: stack overflow can occur in the fx operation by passing a crafted argument due to a missing depth check (bsc#1268123).
  • CVE-2026-46559: heap buffer over-write of a single byte when specifying certain options due to n incorrect check in the JP2 (bsc#1268121).
  • CVE-2026-46692: heap buffer over-write in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268120).
  • CVE-2026-46693: file descriptor hijacking in the server process when a race condition is met via an attacker who can connect to a magick -distribute-cache service (bsc#1268117).
  • CVE-2026-47165: distributed pixel cache was originally designed to operate without a challenge--response authentication model (bsc#1268114).
  • CVE-2026-47166: heap buffer over-read in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268113).
  • CVE-2026-48734: Stack Overflow in MVG decoder (bsc#1268122).
  • CVE-2026-48994: heap buffer over-write due to a missing check of a return value in the MAT decoder on 32-bit systems (bsc#1268111).
  • CVE-2026-49218: denial of service due to a missing check in the DCM decoder (bsc#1268110).
  • CVE-2026-53460: out-of-Memory condition due to a missing check for maximum memory request in AcquireAlignedMemory (bsc#1268108).
  • CVE-2026-53461: out of bounds heap write due to an incorrect loop in the ICON decoder (bsc#1268107).
  • CVE-2026-53463: null pointer deference due to passing incorrect arguments in the distort operation (bsc#1268105).
  • CVE-2026-53464: small memory leak due to providing invalid options to the wand option parser (bsc#1268103).
  • CVE-2026-53466: heap Buffer Over-Read in XCF decoder due to integer conversion overflow (bsc#1270073).
  • CVE-2026-53467: information Disclosure in MNG decoder because allocated memory is left unchanged (bsc#1270074).
  • CVE-2026-55594: stack Overflow in MVG decoder due to missing depth check (bsc#1270077).
  • CVE-2026-55595: infinite Loop in connected-components when providing invalid arguments (bsc#1270079).
  • CVE-2026-55597: heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments (bsc#1270080).
  • CVE-2026-56361: off-by-one origin validation in allows out-of-bounds read in morphology processing (bsc#1270001).
  • CVE-2026-56363: division by Zero in binomial kernel (bsc#1270002).
  • CVE-2026-56364: memory Leak in LoadOpenCLDeviceBenchmark() when parsing malformed XML (bsc#1270003).
  • CVE-2026-56365: memory leak in PNG encoder when writing a MNG image (bsc#1270004).
  • CVE-2026-56367: integer overflow in the PSB (PSD v2) RLE decoding path that causes a heap out-of-bounds read (bsc#1268645).
  • CVE-2026-56368: memory leak in multiple coders that write raw pixel data (bsc#1269064).
  • CVE-2026-56370: out-of-bounds access in ConnectedComponentsImage() when processing connected-components:* artifacts with invalid indices (bsc#1269063).
  • CVE-2026-56371: memory leak in coders/txt.c when processing TXT files with texture attributes (bsc#1268879).
  • CVE-2026-56374: heap-buffer-overflow in FTXT encoder (bsc#1271099).
  • CVE-2026-56376: heap use-after-free in the meta coder can lead to denial of service via specially crafted image files (bsc#1268880).
  • CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878).
  • GHSA-3j4x-rwrx-xxj9: possible use-after-free write in PDB decoder (bsc#1268640).

Список пакетов

SUSE Linux Enterprise Server 15 SP6-LTSS
ImageMagick-7.1.1.21-150600.3.73.1
ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1
ImageMagick-config-7-upstream-secure-7.1.1.21-150600.3.73.1
ImageMagick-config-7-upstream-websafe-7.1.1.21-150600.3.73.1
ImageMagick-devel-7.1.1.21-150600.3.73.1
libMagick++-7_Q16HDRI5-7.1.1.21-150600.3.73.1
libMagick++-devel-7.1.1.21-150600.3.73.1
libMagickCore-7_Q16HDRI10-7.1.1.21-150600.3.73.1
libMagickWand-7_Q16HDRI10-7.1.1.21-150600.3.73.1
perl-PerlMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
ImageMagick-7.1.1.21-150600.3.73.1
ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1
ImageMagick-config-7-upstream-secure-7.1.1.21-150600.3.73.1
ImageMagick-config-7-upstream-websafe-7.1.1.21-150600.3.73.1
ImageMagick-devel-7.1.1.21-150600.3.73.1
libMagick++-7_Q16HDRI5-7.1.1.21-150600.3.73.1
libMagick++-devel-7.1.1.21-150600.3.73.1
libMagickCore-7_Q16HDRI10-7.1.1.21-150600.3.73.1
libMagickWand-7_Q16HDRI10-7.1.1.21-150600.3.73.1
perl-PerlMagick-7.1.1.21-150600.3.73.1

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, a crafted image could result in an out of bounds heap write when writing a yaml or json output, resulting in a crash. This issue has been fixed in version 7.1.2-19.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-21 and 6.9.13-46, a malicious MIFF file could trigger an overflow when a user opens it in the display tool and right-clicks a tile to invoke the Load / Update menu item. This vulnerability is fixed in 7.1.2-21 and 6.9.13-46.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, when writing an IPTC output file a malicious input file could cause an out of bounds read of a single byte. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, due to a missing check in the PSD decoder it would be possible to bypass the list-length resource policy when decoding a PSD image. Other security limits would still apply. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, an off by one in the meta encoder could result in an out of bounds read of a single byte in the meta encoder. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-22, an invalid connected-components:keep-top value could result in a heap buffer over-read when performing the connected components operation. This issue has been patched in versions 6.9.13-48 and 7.1.2-22.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, when performing a polynomial distortion an out of bounds over-read of 24 bytes can occur when specifying specific arguments. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, because of a missing check in the MNG coder it would be possible to read more images than the list limit policy would allow resulting in excessive resource use. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when reading multiple images with different dimensions an out of bounds heap write can occur. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when using LZMA compression in the MIFF encoder an out of bounds write can occur due to a missing check. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, due to a missing check in the MIFF decoder, a crafted file could cause an infinite loop resulting in CPU exhaustion. Versions 7.1.2.23 and 6.9.13-48 fix the issue.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, a crafted MSL image can trigger a heap-use-after-free. Versions 7.1.2.23 and 6.9.13-48 fix the issue.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-23, due to a missing depth check a stack overflow can occur in the fx operation by passing a crafted argument. This issue has been patched in version 7.1.2-23.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an incorrect check in the JP2 will result in an heap buffer over-write of a single byte when specifying certain options. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-write in the server process. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can hijack a file descriptor in the server process when a race condition is met. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, the distributed pixel cache was originally designed to operate without a challenge-response authentication model. This has been changed in versions 6.9.13-48 and 7.1.2-23.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-read in the server process. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, a crafted MVG file could result in a stack overflow due to a missing depth or visited-set check. This issue has been patched in versions 6.9.13-49 and 7.1.2-24.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check of a return value could lead to a heap buffer over-write in the MAT decoder on 32-bit systems. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check in the DCM decoder could result in an image with invalid dimensions and that could cause crashes in other operation. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, a missing check for maximum memory request in AcquireAlignedMemory could trigger an out-of-Memory condition. This issue has been patched in versions 6.9.13-50 and 7.1.2-25.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, an incorrect loop in the ICON decoder can result in an out of bounds heap write resulting in a crash. This issue has been patched in versions 6.9.13-50 and 7.1.2-25.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, when passing incorrect arguments in the distort operation a null pointer deference will occur. This issue has been patched in versions 6.9.13-50 and 7.1.2-25.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, when providing invalid options to the wand option parser a small memory leak will occur. This issue has been patched in version 7.1.2-25.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, an integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is read, potentially resulting in a crash. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, the MNG decoder contains a possible heap information disclosure vulnerability because part of the pixels are left unchanged. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when providing invalid arguments to the connected-components option an infinite loop will occur. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-26, an incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder. This issue has been fixed in version7.1.2-26.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer reads. Attackers can trigger heap buffer overflow by providing incorrect morphology parameters causing single pixel memory access violations.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick before 7.1.2-22 contains a division by zero vulnerability in binomial kernel processing that allows attackers to cause denial of service. An attacker can supply a large binomial kernel value causing integer overflow, resulting in division by zero and application crash.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in coders/psd.c) that causes a heap out-of-bounds read on 32-bit builds. Processing a crafted PSB file can lead to information disclosure or a crash.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. Attackers can trigger access violations by specifying malformed connected-components definitions via CLI, causing denial of service or potential code execution.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each time a crafted TXT file with a texture attribute is processed.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or information disclosure.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. Remote attackers can trigger it by processing specially crafted image files, causing a denial of service.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки

Описание

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1

Ссылки
Уязвимость SUSE-SU-2026:3023-1