Описание
Security update for ImageMagick
This update for ImageMagick fixes the following issues:
- CVE-2022-0284: Fixed heap buffer overread in GetPixelAlpha() in MagickCore/pixel-accessor.h (bsc#1195563).
Список пакетов
openSUSE Leap 15.3
ImageMagick-7.0.7.34-10.21.1
ImageMagick-config-7-SUSE-7.0.7.34-10.21.1
ImageMagick-config-7-upstream-7.0.7.34-10.21.1
ImageMagick-devel-7.0.7.34-10.21.1
ImageMagick-devel-32bit-7.0.7.34-10.21.1
ImageMagick-doc-7.0.7.34-10.21.1
ImageMagick-extra-7.0.7.34-10.21.1
libMagick++-7_Q16HDRI4-7.0.7.34-10.21.1
libMagick++-7_Q16HDRI4-32bit-7.0.7.34-10.21.1
libMagick++-devel-7.0.7.34-10.21.1
libMagick++-devel-32bit-7.0.7.34-10.21.1
libMagickCore-7_Q16HDRI6-7.0.7.34-10.21.1
libMagickCore-7_Q16HDRI6-32bit-7.0.7.34-10.21.1
libMagickWand-7_Q16HDRI6-7.0.7.34-10.21.1
libMagickWand-7_Q16HDRI6-32bit-7.0.7.34-10.21.1
perl-PerlMagick-7.0.7.34-10.21.1
Ссылки
- E-Mail link for openSUSE-SU-2022:0540-1
- SUSE Security Ratings
- SUSE Bug 1195563
- SUSE CVE CVE-2022-0284 page
Описание
A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulnerability is triggered when an attacker passes a specially crafted Tagged Image File Format (TIFF) image to convert it into a PICON file format. This issue can potentially lead to a denial of service and information disclosure.
Затронутые продукты
openSUSE Leap 15.3:ImageMagick-7.0.7.34-10.21.1
openSUSE Leap 15.3:ImageMagick-config-7-SUSE-7.0.7.34-10.21.1
openSUSE Leap 15.3:ImageMagick-config-7-upstream-7.0.7.34-10.21.1
openSUSE Leap 15.3:ImageMagick-devel-32bit-7.0.7.34-10.21.1
Ссылки
- CVE-2022-0284
- SUSE Bug 1195563