Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Mageia 6: MGASA-2019-0033 Moderate: GraphicsMagick DoS And Buffer Overflow

mageia
Calendar Grey January 11, 2019
Dist Mageia Esm H88
GraphicsMagick has released a critical security patch to mitigate risks associated with vulnerabilities, such as buffer overflow and potential denial of service scenarios.
It was discovered that graphicsmagick was subject to vulnerabilites

Summary

It was discovered that graphicsmagick was subject to vulnerabilites. * heap-based buffer overflow in the WriteTGAImage function of tga.c (CVE-2018-20184). * denial of service vulnerability in ReadDIBImage function of coders/dib.c (CVE-2018-20189). * heap-based buffer over-read in the ReadBMPImage function of bmp.c (CVE-2018-20185).

References

- https://bugs.mageia.org/show_bug.cgi?id=24103

- - http://lists.suse.com/pipermail/sle-security-updates/2019-January/005014.html

- https://www.cve.org/CVERecord?id=CVE-2018-20184

- https://www.cve.org/CVERecord?id=CVE-2018-20185

- https://www.cve.org/CVERecord?id=CVE-2018-20189

Resolution

SRPMS

- 6/core/graphicsmagick-1.3.31-1.3.mga6

Publication date: 11 Jan 2019
URL: https://advisories.mageia.org/MGASA-2019-0033.html
Type: security
CVE: CVE-2018-20184, CVE-2018-20185, CVE-2018-20189

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here