Описание
Security update for ImageMagick
This update for ImageMagick fixes the following issue:
- Extend CVE-2026-56379 patch by f63c78b (bsc#1268878).
Список пакетов
SUSE Linux Enterprise Module for Desktop Applications 15 SP7
ImageMagick-7.1.1.43-150700.3.73.1
ImageMagick-config-7-SUSE-7.1.1.43-150700.3.73.1
ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.73.1
ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.73.1
ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.73.1
ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.73.1
ImageMagick-devel-7.1.1.43-150700.3.73.1
libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.73.1
libMagick++-devel-7.1.1.43-150700.3.73.1
libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.73.1
libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.73.1
SUSE Linux Enterprise Module for Development Tools 15 SP7
perl-PerlMagick-7.1.1.43-150700.3.73.1
Ссылки
- Link for SUSE-SU-2026:3336-1
- E-Mail link for SUSE-SU-2026:3336-1
- SUSE Security Ratings
- SUSE Bug 1268878
- SUSE CVE CVE-2026-56379 page
Описание
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.
Затронутые продукты
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:ImageMagick-7.1.1.43-150700.3.73.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:ImageMagick-config-7-SUSE-7.1.1.43-150700.3.73.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.73.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.73.1
Ссылки
- CVE-2026-56379
- SUSE Bug 1268878