Описание
Security update for ImageMagick
This update for ImageMagick fixes the following issue:
- CVE-2026-64685: heap buffer over-read in BGR decoder due to missing end-of-file check (bsc#1272953).
Список пакетов
SUSE Linux Enterprise Module for Desktop Applications 15 SP7
ImageMagick-7.1.1.43-150700.3.79.1
ImageMagick-config-7-SUSE-7.1.1.43-150700.3.79.1
ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.79.1
ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.79.1
ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.79.1
ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.79.1
ImageMagick-devel-7.1.1.43-150700.3.79.1
libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.79.1
libMagick++-devel-7.1.1.43-150700.3.79.1
libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.79.1
libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.79.1
SUSE Linux Enterprise Module for Development Tools 15 SP7
perl-PerlMagick-7.1.1.43-150700.3.79.1
Ссылки
- Link for SUSE-SU-2026:3586-1
- E-Mail link for SUSE-SU-2026:3586-1
- SUSE Security Ratings
- SUSE Bug 1272953
- SUSE CVE CVE-2026-64685 page
Описание
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. This issue has been fixed in version 7.1.2-27.
Затронутые продукты
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:ImageMagick-7.1.1.43-150700.3.79.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:ImageMagick-config-7-SUSE-7.1.1.43-150700.3.79.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.79.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.79.1
Ссылки
- CVE-2026-64685
- SUSE Bug 1272953