Описание
Security update for GraphicsMagick
This update for GraphicsMagick fixes the following issues:
Список пакетов
openSUSE Leap 42.2
openSUSE Leap 42.3
Ссылки
- E-Mail link for openSUSE-SU-2017:3270-1
- SUSE Security Ratings
Описание
When GraphicsMagick 1.3.25 processes a DPX image (with metadata indicating a large width) in coders/dpx.c, a denial of service (OOM) can occur in ReadDPXImage().
Затронутые продукты
Ссылки
- CVE-2017-10799
- SUSE Bug 1047054
- SUSE Bug 1050116
Описание
The ReadDCMImage function in coders\dcm.c in ImageMagick 7.0.6-1 has an integer signedness error leading to excessive memory consumption via a crafted DCM file.
Затронутые продукты
Ссылки
- CVE-2017-12140
- SUSE Bug 1051847
- SUSE Bug 1052764
Описание
ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadDCMImage in coders\dcm.c.
Затронутые продукты
Ссылки
- CVE-2017-12644
- SUSE Bug 1051847
- SUSE Bug 1052764
Описание
ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePDFImage in coders/pdf.c.
Затронутые продукты
Ссылки
- CVE-2017-12662
- SUSE Bug 1052758
Описание
ReadRLEImage in coders/rle.c in GraphicsMagick 1.3.26 mishandles RLE headers that specify too few colors, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
Затронутые продукты
Ссылки
- CVE-2017-14733
- SUSE Bug 1060577
Описание
ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted DICOM image, related to the ability of DCM_ReadNonNativeImages to yield an image list with zero frames.
Затронутые продукты
Ссылки
- CVE-2017-14994
- SUSE Bug 1061587