MGASA-2023-0161 - Updated imagemagick packages fix security vulnerability Publication date: 06 May 2023 URL: https://advisories.mageia.org/MGASA-2023-0161.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-1906 A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service. (CVE-2023-1906) References: - https://bugs.mageia.org/show_bug.cgi?id=31817 - https://lists.suse.com/pipermail/sle-security-updates/2023-April/014519.html - https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-35q2-86c7-9247 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1906 SRPMS: - 8/core/imagemagick-7.1.0.62-1.1.mga8 - 8/tainted/imagemagick-7.1.0.62-1.1.mga8.tainted