MGASA-2023-0161 - Updated imagemagick packages fix security vulnerability

Publication date: 06 May 2023
URL: https://advisories.mageia.org/MGASA-2023-0161.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2023-1906

A heap-based buffer overflow issue was discovered in ImageMagick's
ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An
attacker could pass specially crafted file to convert, triggering an
out-of-bounds read error, allowing an application to crash, resulting in a
denial of service. (CVE-2023-1906)

References:
- https://bugs.mageia.org/show_bug.cgi?id=31817
- https://lists.suse.com/pipermail/sle-security-updates/2023-April/014519.html
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-35q2-86c7-9247
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1906

SRPMS:
- 8/core/imagemagick-7.1.0.62-1.1.mga8
- 8/tainted/imagemagick-7.1.0.62-1.1.mga8.tainted

Mageia 2023-0161: imagemagick security update

A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c

Summary

A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service. (CVE-2023-1906)

References

- https://bugs.mageia.org/show_bug.cgi?id=31817

- https://lists.suse.com/pipermail/sle-security-updates/2023-April/014519.html

- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-35q2-86c7-9247

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1906

Resolution

MGASA-2023-0161 - Updated imagemagick packages fix security vulnerability

SRPMS

- 8/core/imagemagick-7.1.0.62-1.1.mga8

- 8/tainted/imagemagick-7.1.0.62-1.1.mga8.tainted

Severity
Publication date: 06 May 2023
URL: https://advisories.mageia.org/MGASA-2023-0161.html
Type: security
CVE: CVE-2023-1906

Related News