Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3586-1

Опубликовано: 11 авг. 2026
Источник: suse-cvrf

Описание

Security update for ImageMagick

This update for ImageMagick fixes the following issue:

  • CVE-2026-64685: heap buffer over-read in BGR decoder due to missing end-of-file check (bsc#1272953).

Список пакетов

SUSE Linux Enterprise Module for Desktop Applications 15 SP7
ImageMagick-7.1.1.43-150700.3.79.1
ImageMagick-config-7-SUSE-7.1.1.43-150700.3.79.1
ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.79.1
ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.79.1
ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.79.1
ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.79.1
ImageMagick-devel-7.1.1.43-150700.3.79.1
libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.79.1
libMagick++-devel-7.1.1.43-150700.3.79.1
libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.79.1
libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.79.1
SUSE Linux Enterprise Module for Development Tools 15 SP7
perl-PerlMagick-7.1.1.43-150700.3.79.1

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. This issue has been fixed in version 7.1.2-27.


Затронутые продукты
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:ImageMagick-7.1.1.43-150700.3.79.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:ImageMagick-config-7-SUSE-7.1.1.43-150700.3.79.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.79.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.79.1

Ссылки
Уязвимость SUSE-SU-2026:3586-1