Описание
Security update for GraphicsMagick
This update for GraphicsMagick fixes the following issue:
- CVE-2025-55154: integer overflow when performing magnified size calculations in ReadOneMNGIMage can lead to out-of- bounds write (bsc#1248078).
Список пакетов
openSUSE Leap 16.0
GraphicsMagick-1.3.45-160000.13.1
GraphicsMagick-devel-1.3.45-160000.13.1
libGraphicsMagick++-Q16-12-1.3.45-160000.13.1
libGraphicsMagick++-devel-1.3.45-160000.13.1
libGraphicsMagick-Q16-3-1.3.45-160000.13.1
libGraphicsMagick3-config-1.3.45-160000.13.1
libGraphicsMagickWand-Q16-2-1.3.45-160000.13.1
perl-GraphicsMagick-1.3.45-160000.13.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1248078
- SUSE CVE CVE-2025-55154 page
Описание
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (in coders/png.c) are unsafe and can overflow, leading to memory corruption. This issue has been patched in versions 6.9.13-27 and 7.1.2-1.
Затронутые продукты
openSUSE Leap 16.0:GraphicsMagick-1.3.45-160000.13.1
openSUSE Leap 16.0:GraphicsMagick-devel-1.3.45-160000.13.1
openSUSE Leap 16.0:libGraphicsMagick++-Q16-12-1.3.45-160000.13.1
openSUSE Leap 16.0:libGraphicsMagick++-devel-1.3.45-160000.13.1
Ссылки
- CVE-2025-55154
- SUSE Bug 1248078
- SUSE Bug 1253311