GraphicsMagick was updated to 1.3.29:
* Security Fixes:
- GraphicsMagick is now participating in Google's oss-fuzz project
- JNG: Require that the embedded JPEG image have the same dimensions as
the JNG image as provided by JHDR. Avoids a heap write overflow.
- MNG: Arbitrarily limit the number of loops which may be requested by
the MNG LOOP chunk to 512 loops, and provide the '-define
mng:maximum-loops=value' option in case the user wants to change the
limit. This fixes a denial of service caused by large LOOP
specifications.
* Bug fixes:
- DICOM: Pre/post rescale functions are temporarily disabled (until the
implementation is fixed).
- JPEG: Fix regression in last release in which reading some JPEG files
produces the error "Improper call to JPEG library in state 201".
- ICON: Some DIB-based Windows ICON files were reported as corrupt to an
unexpectedly missing opacity mask image.
...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2018-518=1
- openSUSE Leap 15.0 (x86_64):
GraphicsMagick-1.3.29-lp150.3.3.1
GraphicsMagick-debuginfo-1.3.29-lp150.3.3.1
GraphicsMagick-debugsource-1.3.29-lp150.3.3.1
GraphicsMagick-devel-1.3.29-lp150.3.3.1
libGraphicsMagick++-Q16-12-1.3.29-lp150.3.3.1
libGraphicsMagick++-Q16-12-debuginfo-1.3.29-lp150.3.3.1
libGraphicsMagick++-devel-1.3.29-lp150.3.3.1
libGraphicsMagick-Q16-3-1.3.29-lp150.3.3.1
libGraphicsMagick-Q16-3-debuginfo-1.3.29-lp150.3.3.1
libGraphicsMagick3-config-1.3.29-lp150.3.3.1
libGraphicsMagickWand-Q16-2-1.3.29-lp150.3.3.1
libGraphicsMagickWand-Q16-2-debuginfo-1.3.29-lp150.3.3.1
perl-GraphicsMagick-1.3.29-lp150.3.3.1
perl-GraphicsMagick-debuginfo-1.3.29-lp150.3.3.1
https://bugzilla.suse.com/1094352
--
Get the latest Linux and open source security news straight to your inbox.