Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian LTS: DLA-3429-1 Severe: Imagemagick Buffer Overflow DoS

debian lts
Calendar Grey May 21, 2023
Dist Debian Esm H88
Debian LTS Advisory DLA-3429-1 highlights vulnerabilities in imagemagick, enhancing the security framework for image manipulation software.
Multiple vulnerabilities were fixed in imagemagick, a software suite, used for editing and manipulating digital images

Summary

CVE-2021-20176

A divide by zero was found in gem.c file.

CVE-2021-20241

A divide by zero was found in jp2 coder.

CVE-2021-20243

A divide by zero was found in dcm coder.

CVE-2021-20244

A divide by zero was found in fx.c.

CVE-2021-20245

A divide by zero was found in webp coder.

CVE-2021-20246

A divide by zero was found in resample.c.

CVE-2021-20309

A divide by zero was found in WaveImage.c

CVE-2021-20312

An integer overflow was found in WriteTHUMBNAILImage()
of coders/thumbnail.c

CVE-2021-20313

A potential cipher leak was found when the calculate
signatures in TransformSignature().

CVE-2021-39212

A policy bypass was found for postscript files.

CVE-2022-28463

A bufer overflow was found in buffer overflow in cin coder.

CVE-2022-32545

A undefined behavior (conversion outside the range of
representable values of type 'unsigned char') was found in psd
file handling.

CVE-2022-32546

A undefined behavior (conversion outside the range of

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: imagemagick
Version: 8:6.9.10.23+dfsg-2.1+deb10u5
CVE ID: CVE-2021-20176 CVE-2021-20241 CVE-2021-20243 CVE-2021-20244
Debian Bug: 996588 1013282 1016442

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here