Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

openSUSE Leap 15.0: 2018:1421-1 Moderate: GraphicsMagick Security Fix

opensuse
Calendar Grey May 25, 2018
Dist Opensuse Esm H88
An upgrade for GraphicsMagick in openSUSE resolves vulnerabilities related to heap overflow and denial of service risks.
An update that contains security fixes can now be installed.

Description

GraphicsMagick was updated to 1.3.29:

* Security Fixes:

- GraphicsMagick is now participating in Google's oss-fuzz project

- JNG: Require that the embedded JPEG image have the same dimensions as

the JNG image as provided by JHDR. Avoids a heap write overflow.

- MNG: Arbitrarily limit the number of loops which may be requested by

the MNG LOOP chunk to 512 loops, and provide the '-define

mng:maximum-loops=value' option in case the user wants to change the

limit. This fixes a denial of service caused by large LOOP

specifications.

* Bug fixes:

- DICOM: Pre/post rescale functions are temporarily disabled (until the

implementation is fixed).

- JPEG: Fix regression in last release in which reading some JPEG files

produces the error "Improper call to JPEG library in state 201".

- ICON: Some DIB-based Windows ICON files were reported as corrupt to an

unexpectedly missing opacity mask image.

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2018-518=1

Package List

- openSUSE Leap 15.0 (x86_64):

GraphicsMagick-1.3.29-lp150.3.3.1

GraphicsMagick-debuginfo-1.3.29-lp150.3.3.1

GraphicsMagick-debugsource-1.3.29-lp150.3.3.1

GraphicsMagick-devel-1.3.29-lp150.3.3.1

libGraphicsMagick++-Q16-12-1.3.29-lp150.3.3.1

libGraphicsMagick++-Q16-12-debuginfo-1.3.29-lp150.3.3.1

libGraphicsMagick++-devel-1.3.29-lp150.3.3.1

libGraphicsMagick-Q16-3-1.3.29-lp150.3.3.1

libGraphicsMagick-Q16-3-debuginfo-1.3.29-lp150.3.3.1

libGraphicsMagick3-config-1.3.29-lp150.3.3.1

libGraphicsMagickWand-Q16-2-1.3.29-lp150.3.3.1

libGraphicsMagickWand-Q16-2-debuginfo-1.3.29-lp150.3.3.1

perl-GraphicsMagick-1.3.29-lp150.3.3.1

perl-GraphicsMagick-debuginfo-1.3.29-lp150.3.3.1

References

https://bugzilla.suse.com/1094352

--

Announcement ID: openSUSE-SU-2018:1421-1
Rating: moderate
Affected Products: openSUSE Leap 15.0

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here