Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

openSUSE 13.2: SUSE-2016:1261-1 Important: ImageMagick Critical Issues

opensuse
Calendar Grey May 7, 2016
Scroller Opensuse
A crucial firmware enhancement targeting several flaws in ImageMagick for openSUSE 13.2. Implement updates without delay.
An update that fixes 5 vulnerabilities is now available

Description

This update for ImageMagick fixes the following issues:

The update disables various insecure coders [boo#978061] These fix issues

tracked in CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717,

CVE-2016-3718

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.2:

zypper in -t patch openSUSE-2016-569=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.2 (i586 x86_64):

ImageMagick-6.8.9.8-18.1

ImageMagick-debuginfo-6.8.9.8-18.1

ImageMagick-debugsource-6.8.9.8-18.1

ImageMagick-devel-6.8.9.8-18.1

ImageMagick-extra-6.8.9.8-18.1

ImageMagick-extra-debuginfo-6.8.9.8-18.1

libMagick++-6_Q16-5-6.8.9.8-18.1

libMagick++-6_Q16-5-debuginfo-6.8.9.8-18.1

libMagick++-devel-6.8.9.8-18.1

libMagickCore-6_Q16-2-6.8.9.8-18.1

libMagickCore-6_Q16-2-debuginfo-6.8.9.8-18.1

libMagickWand-6_Q16-2-6.8.9.8-18.1

libMagickWand-6_Q16-2-debuginfo-6.8.9.8-18.1

perl-PerlMagick-6.8.9.8-18.1

perl-PerlMagick-debuginfo-6.8.9.8-18.1

- openSUSE 13.2 (noarch):

ImageMagick-doc-6.8.9.8-18.1

- openSUSE 13.2 (x86_64):

ImageMagick-devel-32bit-6.8.9.8-18.1

libMagick++-6_Q16-5-32bit-6.8.9.8-18.1

libMagick++-6_Q16-5-debuginfo-32bit-6.8.9.8-18.1

libMagick++-devel-32bit-6.8.9.8-18.1

libMagickCore-6_Q16-2-32bit-6.8.9.8-18.1

libMagickCore-6_Q16-2-debuginfo-32bit-6.8.9.8-18.1

libMagickWand-6_Q16-2-32bit-6.8.9.8-18.1

libMagickWand-6_Q16-2-debuginfo-32bit-6.8.9.8-18.1

References

https://www.suse.com/security/cve/CVE-2016-3714.html

https://www.suse.com/security/cve/CVE-2016-3715.html

https://www.suse.com/security/cve/CVE-2016-3716.html

https://www.suse.com/security/cve/CVE-2016-3717.html

https://www.suse.com/security/cve/CVE-2016-3718.html

https://bugzilla.suse.com/978061

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:1261-1
Rating: important
Affected Products: openSUSE 13.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.