Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21426-1

Опубликовано: 22 июл. 2026
Источник: suse-cvrf

Описание

Security update for ImageMagick

This update for ImageMagick fixes the following issues

  • CVE-2026-56375: Possible memory leak in ASHLAR coder when action fails (bsc#1271495).
  • CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878).
  • CVE-2026-61464: Heap Buffer Over-Write in X11 import with crafted window title (bsc#1271496).
  • CVE-2026-61859: Policy Bypass in script operation due to missing checks (bsc#1271497).
  • CVE-2026-61860: Use-After-Free when freetype initialization fails (bsc#1271494).
  • CVE-2026-61862: Information Disclosure when printing profiles with debug enabled (bsc#1271493).
  • CVE-2026-61863: Memory Leak in TIFF encoder when a temporary file could not be created (bsc#1271492).
  • CVE-2026-61864: Memory Leak in color transformation to log colorspace when operation fails (bsc#1271491).
  • CVE-2026-61865: Memory Leak in hough lines operation when an operation fails (bsc#1271490).
  • CVE-2026-61866: Memory Leak in JNG encoder when a blob could not be opened (bsc#1271489).
  • CVE-2026-61867: Memory Leak in TIFF encoder when an allocation fails (bsc#1271488).
  • CVE-2026-61868: Memory Leak in YUV decoder when opening of blob fails (bsc#1271487).
  • CVE-2026-61869: Memory Leak in MIFF encoder when allocation fails (bsc#1271486).
  • CVE-2026-61871: Memory Leak in ICON decoder when allocation fails (bsc#1271485).
  • CVE-2026-61872: Memory Leak in TIFF encoder when invalid tiff:tile-geometry is specified (bsc#1271484).

Список пакетов

openSUSE Leap 16.0
ImageMagick-7.1.2.0-160000.13.1
ImageMagick-config-7-SUSE-7.1.2.0-160000.13.1
ImageMagick-config-7-upstream-limited-7.1.2.0-160000.13.1
ImageMagick-config-7-upstream-open-7.1.2.0-160000.13.1
ImageMagick-config-7-upstream-secure-7.1.2.0-160000.13.1
ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.13.1
ImageMagick-devel-7.1.2.0-160000.13.1
ImageMagick-doc-7.1.2.0-160000.13.1
ImageMagick-extra-7.1.2.0-160000.13.1
libMagick++-7_Q16HDRI5-7.1.2.0-160000.13.1
libMagick++-devel-7.1.2.0-160000.13.1
libMagickCore-7_Q16HDRI10-7.1.2.0-160000.13.1
libMagickWand-7_Q16HDRI10-7.1.2.0-160000.13.1
perl-PerlMagick-7.1.2.0-160000.13.1

Описание

ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers can trigger failed actions to exhaust memory resources and cause denial of service.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.13.1

Ссылки

Описание

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.13.1

Ссылки

Описание

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which can result in heap memory corruption and denial of service.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.13.1

Ссылки

Описание

ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.13.1

Ссылки

Описание

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to use memory that was already freed. This can be triggered during image processing and may lead to a denial of service.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.13.1

Ссылки

Описание

ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This behavior occurs when debug output is enabled.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.13.1

Ссылки

Описание

ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a temporary file cannot be created, resulting in a small memory leak.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.13.1

Ссылки

Описание

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log colorspace: when the operation fails, a small amount of memory is not released.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.13.1

Ссылки

Описание

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation: when a specific operation fails, a small memory leak occurs.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.13.1

Ссылки

Описание

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.13.1

Ссылки

Описание

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory allocation fails. Attackers can trigger allocation failures during TIFF image processing to cause memory exhaustion and denial of service.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.13.1

Ссылки

Описание

ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when opening of the blob fails. Repeated triggering can lead to resource exhaustion (denial of service).


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.13.1

Ссылки

Описание

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the MIFF encoder that occurs when a memory allocation fails during MIFF image processing, which can lead to denial of service.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.13.1

Ссылки

Описание

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file that triggers an allocation failure leaks memory, which may lead to a denial of service.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.13.1

Ссылки

Описание

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the TIFF encoder when an invalid tiff:tile-geometry is specified. Supplying malformed tile geometry parameters causes allocated memory not to be released, which can lead to increased memory consumption.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.13.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.13.1

Ссылки