Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 26: 2017-02008fed70 Moderate: GraphicsMagick Memory Issues

fedora
Calendar Grey July 8, 2017
Dist Fedora Esm H88
Fedora 26 has released a critical security patch for GraphicsMagick, targeting significant memory-related flaws and vulnerabilities linked to buffer overflows.
New stable upstream release, primarily includes security fixes for CVE-2017-10794, CVE-2017-10799, CVE-2017-10800 See also http://www.graphicsmagick.org/NEWS.html#july-4-2017

Summary

GraphicsMagick is a comprehensive image processing package which is initially

based on ImageMagick 5.5.2, but which has undergone significant re-work by

the GraphicsMagick Group to significantly improve the quality and performance

of the software.

New stable upstream release, primarily includes security fixes for

CVE-2017-10794, CVE-2017-10799, CVE-2017-10800 See also

http://www.graphicsmagick.org/NEWS.html#july-4-2017

[ 1 ] Bug #1467378 - CVE-2017-10800 GraphicsMagick: out of memory in ReadMATImage() function

https://bugzilla.redhat.com/show_bug.cgi?id=1467378

[ 2 ] Bug #1467372 - CVE-2017-10799 GraphicsMagick: out of memory in ReadDPXImage() function

https://bugzilla.redhat.com/show_bug.cgi?id=1467372

[ 3 ] Bug #1467655 - CVE-2017-10794 GraphicsMagick: buffer overflow in QuantumTransferMode

https://bugzilla.redhat.com/show_bug.cgi?id=1467655

su -c 'dnf upgrade GraphicsMagick' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 26
Version: 1.3.26
Release: 1.fc26
Summary: An ImageMagick fork, offering faster image generation and better quality

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here