Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

openSUSE 42.3: 2018:1860-1 Moderate: ImageMagick Buffer Overflows Fixes

opensuse
Calendar Grey June 30, 2018
Dist Opensuse Esm H88
ImageMagick's latest update fixes eight vulnerabilities, such as buffer overflows and memory leaks, and offers detailed installation guidance for users
An update that fixes 8 vulnerabilities is now available.

Description

This update for ImageMagick fixes the following issues:

These security issues were fixed:

- CVE-2017-13758: Prevent heap-based buffer overflow in the TracePoint()

function (bsc#1056277).

- CVE-2017-10928: Prevent heap-based buffer over-read in the GetNextToken

function that allowed remote attackers to obtain sensitive information

from process memory or possibly have unspecified other impact via a

crafted SVG document (bsc#1047356).

- CVE-2018-9133: Long compute times in the tiff decoder have been fixed

(bsc#1087820).

- CVE-2018-11251: Heap-based buffer over-read in ReadSUNImage in

coders/sun.c, which allows attackers to cause denial of service

(bsc#1094237).

- CVE-2017-18271: Infinite loop in the function ReadMIFFImage in

coders/miff.c, which allows attackers to cause a denial of service

(bsc#1094204).

- CVE-2018-11655: Memory leak in the GetImagePixelCache in

MagickCore/cache.c was fixed (bsc#1095730)

-...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-690=1

Package List

- openSUSE Leap 42.3 (i586 x86_64):

ImageMagick-6.8.8.1-64.1

ImageMagick-debuginfo-6.8.8.1-64.1

ImageMagick-debugsource-6.8.8.1-64.1

ImageMagick-devel-6.8.8.1-64.1

ImageMagick-extra-6.8.8.1-64.1

ImageMagick-extra-debuginfo-6.8.8.1-64.1

libMagick++-6_Q16-3-6.8.8.1-64.1

libMagick++-6_Q16-3-debuginfo-6.8.8.1-64.1

libMagick++-devel-6.8.8.1-64.1

libMagickCore-6_Q16-1-6.8.8.1-64.1

libMagickCore-6_Q16-1-debuginfo-6.8.8.1-64.1

libMagickWand-6_Q16-1-6.8.8.1-64.1

libMagickWand-6_Q16-1-debuginfo-6.8.8.1-64.1

perl-PerlMagick-6.8.8.1-64.1

perl-PerlMagick-debuginfo-6.8.8.1-64.1

- openSUSE Leap 42.3 (noarch):

ImageMagick-doc-6.8.8.1-64.1

- openSUSE Leap 42.3 (x86_64):

ImageMagick-devel-32bit-6.8.8.1-64.1

libMagick++-6_Q16-3-32bit-6.8.8.1-64.1

libMagick++-6_Q16-3-debuginfo-32bit-6.8.8.1-64.1

libMagick++-devel-32bit-6.8.8.1-64.1

libMagickCore-6_Q16-1-32bit-6.8.8.1-64.1

libMagickCore-6_Q16-1-debuginfo-32bit-6.8.8.1-64.1

libMagickWand-6_Q16-1-32bit-6.8.8.1-64.1

libMagickWand-6_Q16-1-debuginfo-32bit-6.8.8.1-64.1

References

https://www.suse.com/security/cve/CVE-2017-10928.html

https://www.suse.com/security/cve/CVE-2017-13758.html

https://www.suse.com/security/cve/CVE-2017-18271.html

https://www.suse.com/security/cve/CVE-2018-10804.html

https://www.suse.com/security/cve/CVE-2018-10805.html

https://www.suse.com/security/cve/CVE-2018-11251.html

https://www.suse.com/security/cve/CVE-2018-11655.html

https://www.suse.com/security/cve/CVE-2018-9133.html

https://bugzilla.suse.com/show_bug.cgi?id=1047356

https://bugzilla.suse.com/show_bug.cgi?id=1056277

https://bugzilla.suse.com/show_bug.cgi?id=1087820

https://bugzilla.suse.com/show_bug.cgi?id=1094204

https://bugzilla.suse.com/show_bug.cgi?id=1094237

https://bugzilla.suse.com/show_bug.cgi?id=1095730

https://bugzilla.suse.com/show_bug.cgi?id=1095812

https://bugzilla.suse.com/show_bug.cgi?id=1095813

--

Announcement ID: openSUSE-SU-2018:1860-1
Rating: moderate
Affected Products: openSUSE Leap 42.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here