Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2018:1123-1

Опубликовано: 02 мая 2018
Источник: suse-cvrf

Описание

Security update for GraphicsMagick

This update for GraphicsMagick fixes the following issues:

  • security update (core)

    • CVE-2018-6799: The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause a denial of service (heap overwrite) or possibly have unspecified other impact via a crafted image file, because a pixel staging area is not used. [boo#1080522]
  • security update (png.c)

    • CVE-2018-9018: In GraphicsMagick 1.3.28, there is a divide-by-zero in the ReadMNGImage function of coders/png.c. Remote attackers could leverage this vulnerability to cause a crash and denial of service via a crafted mng file. [boo#1086773]
  • security update (gif.c)

    • CVE-2017-18254: An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function WriteGIFImage in coders/gif.c, which allow remote attackers to cause a denial of service via a crafted file. [boo#1087027]
  • security update (pcd.c)

    • CVE-2017-18251: An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function ReadPCDImage in coders/pcd.c, which allow remote attackers to cause a denial of service via a crafted file. [boo#1087037]

    • CVE-2017-18229: An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allows attackers to cause a denial of service via a crafted file, because file size is not properly used to restrict scanline, strip, and tile allocations. [boo#1085236]

    • CVE-2017-11641: GraphicsMagick 1.3.26 has a Memory Leak in the PersistCache function in magick/pixel_cache.c during writing of Magick Persistent Cache (MPC) files.[boo#1050623]

    • CVE-2017-13066: GraphicsMagick 1.3.26 has a memory leak vulnerability in the function CloneImage in magick/image.c. [boo#1055010]

    • CVE-2018-10177: Specially crafted PNG images may have triggered an infinite loop [bsc#1089781]

Список пакетов

openSUSE Leap 42.3
GraphicsMagick-1.3.25-87.1
GraphicsMagick-devel-1.3.25-87.1
libGraphicsMagick++-Q16-12-1.3.25-87.1
libGraphicsMagick++-devel-1.3.25-87.1
libGraphicsMagick-Q16-3-1.3.25-87.1
libGraphicsMagick3-config-1.3.25-87.1
libGraphicsMagickWand-Q16-2-1.3.25-87.1
perl-GraphicsMagick-1.3.25-87.1

Описание

GraphicsMagick 1.3.26 has a Memory Leak in the PersistCache function in magick/pixel_cache.c during writing of Magick Persistent Cache (MPC) files.


Затронутые продукты
openSUSE Leap 42.3:GraphicsMagick-1.3.25-87.1
openSUSE Leap 42.3:GraphicsMagick-devel-1.3.25-87.1
openSUSE Leap 42.3:libGraphicsMagick++-Q16-12-1.3.25-87.1
openSUSE Leap 42.3:libGraphicsMagick++-devel-1.3.25-87.1

Ссылки

Описание

GraphicsMagick 1.3.26 has a memory leak vulnerability in the function CloneImage in magick/image.c.


Затронутые продукты
openSUSE Leap 42.3:GraphicsMagick-1.3.25-87.1
openSUSE Leap 42.3:GraphicsMagick-devel-1.3.25-87.1
openSUSE Leap 42.3:libGraphicsMagick++-Q16-12-1.3.25-87.1
openSUSE Leap 42.3:libGraphicsMagick++-devel-1.3.25-87.1

Ссылки

Описание

An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allows attackers to cause a denial of service via a crafted file, because file size is not properly used to restrict scanline, strip, and tile allocations.


Затронутые продукты
openSUSE Leap 42.3:GraphicsMagick-1.3.25-87.1
openSUSE Leap 42.3:GraphicsMagick-devel-1.3.25-87.1
openSUSE Leap 42.3:libGraphicsMagick++-Q16-12-1.3.25-87.1
openSUSE Leap 42.3:libGraphicsMagick++-devel-1.3.25-87.1

Ссылки

Описание

An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function ReadPCDImage in coders/pcd.c, which allow remote attackers to cause a denial of service via a crafted file.


Затронутые продукты
openSUSE Leap 42.3:GraphicsMagick-1.3.25-87.1
openSUSE Leap 42.3:GraphicsMagick-devel-1.3.25-87.1
openSUSE Leap 42.3:libGraphicsMagick++-Q16-12-1.3.25-87.1
openSUSE Leap 42.3:libGraphicsMagick++-devel-1.3.25-87.1

Ссылки

Описание

An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function WriteGIFImage in coders/gif.c, which allow remote attackers to cause a denial of service via a crafted file.


Затронутые продукты
openSUSE Leap 42.3:GraphicsMagick-1.3.25-87.1
openSUSE Leap 42.3:GraphicsMagick-devel-1.3.25-87.1
openSUSE Leap 42.3:libGraphicsMagick++-Q16-12-1.3.25-87.1
openSUSE Leap 42.3:libGraphicsMagick++-devel-1.3.25-87.1

Ссылки

Описание

In ImageMagick 7.0.7-28, there is an infinite loop in the ReadOneMNGImage function of the coders/png.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted mng file.


Затронутые продукты
openSUSE Leap 42.3:GraphicsMagick-1.3.25-87.1
openSUSE Leap 42.3:GraphicsMagick-devel-1.3.25-87.1
openSUSE Leap 42.3:libGraphicsMagick++-Q16-12-1.3.25-87.1
openSUSE Leap 42.3:libGraphicsMagick++-devel-1.3.25-87.1

Ссылки

Описание

The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause a denial of service (heap overwrite) or possibly have unspecified other impact via a crafted image file, because a pixel staging area is not used.


Затронутые продукты
openSUSE Leap 42.3:GraphicsMagick-1.3.25-87.1
openSUSE Leap 42.3:GraphicsMagick-devel-1.3.25-87.1
openSUSE Leap 42.3:libGraphicsMagick++-Q16-12-1.3.25-87.1
openSUSE Leap 42.3:libGraphicsMagick++-devel-1.3.25-87.1

Ссылки

Описание

In GraphicsMagick 1.3.28, there is a divide-by-zero in the ReadMNGImage function of coders/png.c. Remote attackers could leverage this vulnerability to cause a crash and denial of service via a crafted mng file.


Затронутые продукты
openSUSE Leap 42.3:GraphicsMagick-1.3.25-87.1
openSUSE Leap 42.3:GraphicsMagick-devel-1.3.25-87.1
openSUSE Leap 42.3:libGraphicsMagick++-Q16-12-1.3.25-87.1
openSUSE Leap 42.3:libGraphicsMagick++-devel-1.3.25-87.1

Ссылки