Описание
Security update for ImageMagick
This update for ImageMagick fixes the following issues:
- CVE-2021-20309: Division by zero in WaveImage() of MagickCore/visual-effects. (bsc#1184624)
- CVE-2021-20311: Division by zero in sRGBTransformImage() in MagickCore/colorspace.c (bsc#1184626)
- CVE-2021-20312: Integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c (bsc#1184627)
- CVE-2021-20313: Cipher leak when the calculating signatures in TransformSignatureof MagickCore/signature.c (bsc#1184628)
This update was imported from the SUSE:SLE-15-SP2:Update update project.
Список пакетов
openSUSE Leap 15.2
Ссылки
- E-Mail link for openSUSE-SU-2021:0606-1
- SUSE Security Ratings
- SUSE Bug 1184624
- SUSE Bug 1184626
- SUSE Bug 1184627
- SUSE Bug 1184628
- SUSE CVE CVE-2021-20309 page
- SUSE CVE CVE-2021-20311 page
- SUSE CVE CVE-2021-20312 page
- SUSE CVE CVE-2021-20313 page
Описание
A flaw was found in ImageMagick in versions before 7.0.11 and before 6.9.12, where a division by zero in WaveImage() of MagickCore/visual-effects.c may trigger undefined behavior via a crafted image file submitted to an application using ImageMagick. The highest threat from this vulnerability is to system availability.
Затронутые продукты
Ссылки
- CVE-2021-20309
- SUSE Bug 1184624
Описание
A flaw was found in ImageMagick in versions before 7.0.11, where a division by zero in sRGBTransformImage() in the MagickCore/colorspace.c may trigger undefined behavior via a crafted image file that is submitted by an attacker processed by an application using ImageMagick. The highest threat from this vulnerability is to system availability.
Затронутые продукты
Ссылки
- CVE-2021-20311
- SUSE Bug 1184626
Описание
A flaw was found in ImageMagick in versions 7.0.11, where an integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c may trigger undefined behavior via a crafted image file that is submitted by an attacker and processed by an application using ImageMagick. The highest threat from this vulnerability is to system availability.
Затронутые продукты
Ссылки
- CVE-2021-20312
- SUSE Bug 1184627
Описание
A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. The highest threat from this vulnerability is to data confidentiality.
Затронутые продукты
Ссылки
- CVE-2021-20313
- SUSE Bug 1184628