Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21635-1

Опубликовано: 24 авг. 2026
Источник: suse-cvrf

Описание

Security update for ImageMagick

This update for ImageMagick fixes the following issues:

  • CVE-2026-56365: memory leak in the PNG encoder when writing MNG images (bsc#1270004).
  • CVE-2026-62343: heap buffer overwrite in morphology operation when an invalid kernel is provided (bsc#1272575).
  • CVE-2026-62363: heap buffer overwrite in fx operation when processing a crafted argument (bsc#1272582).
  • CVE-2026-62946: integer overflow in JNX decoder leading to heap buffer overwrite when extremely large files are processed on 32-bit builds (bsc#1272580).
  • CVE-2026-66011: memory leak in the magick command-line interface when invalid options are provided (bsc#1272577).
  • CVE-2026-64685: heap buffer overread in BGR decoder due to missing end-of-file check (bsc#1272953).
  • Code injection in HTML encoder due to incomplete fix of CVE-2026-25797 (bsc#1272579).

Список пакетов

openSUSE Leap 16.0
ImageMagick-7.1.2.0-160000.14.1
ImageMagick-config-7-SUSE-7.1.2.0-160000.14.1
ImageMagick-config-7-upstream-limited-7.1.2.0-160000.14.1
ImageMagick-config-7-upstream-open-7.1.2.0-160000.14.1
ImageMagick-config-7-upstream-secure-7.1.2.0-160000.14.1
ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.14.1
ImageMagick-devel-7.1.2.0-160000.14.1
ImageMagick-doc-7.1.2.0-160000.14.1
ImageMagick-extra-7.1.2.0-160000.14.1
libMagick++-7_Q16HDRI5-7.1.2.0-160000.14.1
libMagick++-devel-7.1.2.0-160000.14.1
libMagickCore-7_Q16HDRI10-7.1.2.0-160000.14.1
libMagickWand-7_Q16HDRI10-7.1.2.0-160000.14.1
perl-PerlMagick-7.1.2.0-160000.14.1

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the ps coders, responsible for writing PostScript files, fails to sanitize the input before writing it into the PostScript header. An attacker can provide a malicous file and inject arbitrary PostScript code. When the resulting file is processed by a printer or a viewer (like Ghostscript), the injected code is interpreted and executed. The html encoder does not properly escape strings that are written to in the html document. An attacker can provide a malicious file and injection arbitrary html code. Versions 7.1.2-15 and 6.9.13-40 contain a patch.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.14.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.14.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.14.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.14.1

Ссылки

Описание

ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.14.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.14.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.14.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.14.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.14.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.14.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.14.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.14.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has been fixed in version 7.1.2-27.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.14.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.14.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.14.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.14.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. This issue has been fixed in versions 6.9.13-52 and 7.1.2-27.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.14.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.14.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.14.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.14.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. This issue has been fixed in version 7.1.2-27.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.14.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.14.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.14.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.14.1

Ссылки

Описание

ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.14.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.14.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.14.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.14.1

Ссылки
Уязвимость openSUSE-SU-2026:21635-1