Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

openSUSE Leap 42.3: 2018:2811-1 Moderate: ImageMagick DoS and Memory Leak

opensuse
Calendar Grey September 24, 2018
Dist Opensuse Esm H88
openSUSE Security Update: Security update for ImageMagick __________________________________________
An update that solves 6 vulnerabilities and has one errata is now available.

Description

This update for ImageMagick fixes the following issues:

The following security vulnerabilities were fixed:

- CVE-2018-16329: Prevent NULL pointer dereference in the

GetMagickProperty function leading to DoS (bsc#1106858)

- CVE-2018-16323: ReadXBMImage left data uninitialized when processing an

XBM file that has a negative pixel value. If the affected code was used

as a library loaded into a process that includes sensitive information,

that information sometimes can be leaked via the image data (bsc#1106855)

- CVE-2018-14434: Fixed a memory leak for a colormap in WriteMPCImage

(bsc#1102003)

- CVE-2018-14435: Fixed a memory leak in DecodeImage in coders/pcd.c

(bsc#1102007)

- CVE-2018-14436: Fixed a memory leak in ReadMIFFImage in coders/miff.c

(bsc#1102005)

- CVE-2018-14437: Fixed a memory leak in parse8BIM in coders/meta.c

(bsc#1102004)

- Disable PS, PS2, PS3, XPS and PDF coders in default policy.xml

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-1038=1

Package List

- openSUSE Leap 42.3 (i586 x86_64):

ImageMagick-6.8.8.1-67.1

ImageMagick-debuginfo-6.8.8.1-67.1

ImageMagick-debugsource-6.8.8.1-67.1

ImageMagick-devel-6.8.8.1-67.1

ImageMagick-extra-6.8.8.1-67.1

ImageMagick-extra-debuginfo-6.8.8.1-67.1

libMagick++-6_Q16-3-6.8.8.1-67.1

libMagick++-6_Q16-3-debuginfo-6.8.8.1-67.1

libMagick++-devel-6.8.8.1-67.1

libMagickCore-6_Q16-1-6.8.8.1-67.1

libMagickCore-6_Q16-1-debuginfo-6.8.8.1-67.1

libMagickWand-6_Q16-1-6.8.8.1-67.1

libMagickWand-6_Q16-1-debuginfo-6.8.8.1-67.1

perl-PerlMagick-6.8.8.1-67.1

perl-PerlMagick-debuginfo-6.8.8.1-67.1

- openSUSE Leap 42.3 (x86_64):

ImageMagick-devel-32bit-6.8.8.1-67.1

libMagick++-6_Q16-3-32bit-6.8.8.1-67.1

libMagick++-6_Q16-3-debuginfo-32bit-6.8.8.1-67.1

libMagick++-devel-32bit-6.8.8.1-67.1

libMagickCore-6_Q16-1-32bit-6.8.8.1-67.1

libMagickCore-6_Q16-1-debuginfo-32bit-6.8.8.1-67.1

libMagickWand-6_Q16-1-32bit-6.8.8.1-67.1

libMagickWand-6_Q16-1-debuginfo-32bit-6.8.8.1-67.1

- openSUSE Leap 42.3 (noarch):

ImageMagick-doc-6.8.8.1-67.1

References

https://www.suse.com/security/cve/CVE-2018-14434.html

https://www.suse.com/security/cve/CVE-2018-14435.html

https://www.suse.com/security/cve/CVE-2018-14436.html

https://www.suse.com/security/cve/CVE-2018-14437.html

https://www.suse.com/security/cve/CVE-2018-16323.html

https://www.suse.com/security/cve/CVE-2018-16329.html

https://bugzilla.suse.com/1102003

https://bugzilla.suse.com/1102004

https://bugzilla.suse.com/1102005

https://bugzilla.suse.com/1102007

https://bugzilla.suse.com/1105592

https://bugzilla.suse.com/1106855

https://bugzilla.suse.com/1106858

--

Announcement ID: openSUSE-SU-2018:2811-1
Rating: moderate
Affected Products: openSUSE Leap 42.3 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here