Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

openSUSE 15: 2018:3014-1 Low: ImageMagick DoS Security Fixes

opensuse
Calendar Grey October 5, 2018
Dist Opensuse Esm H88
The latest openSUSE security update for ImageMagick addresses 10 vulnerabilities related to denial of service, enhancing user stability and security architecture
An update that fixes 10 vulnerabilities is now available.

Description

This update for ImageMagick fixes the following security issues:

- CVE-2018-16413: Prevent heap-based buffer over-read in the

PushShortPixel function leading to DoS (bsc#1106989)

- CVE-2018-16329: Prevent NULL pointer dereference in the

GetMagickProperty function leading to DoS (bsc#1106858).

- CVE-2018-16328: Prevent NULL pointer dereference exists in the

CheckEventLogging function leading to DoS (bsc#1106857).

- CVE-2018-16323: ReadXBMImage left data uninitialized when processing an

XBM file that has a negative pixel value. If the affected code was used

as a library loaded into a process that includes sensitive information,

that information sometimes can be leaked via the image data (bsc#1106855)

- CVE-2018-16642: The function InsertRow allowed remote attackers to cause

a denial of service via a crafted image file due to an out-of-bounds

write (bsc#1107616)

- CVE-2018-16640: Prevent memory leak in the function...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2018-1108=1

Package List

- openSUSE Leap 15.0 (i586 x86_64):

ImageMagick-7.0.7.34-lp150.2.15.1

ImageMagick-debuginfo-7.0.7.34-lp150.2.15.1

ImageMagick-debugsource-7.0.7.34-lp150.2.15.1

ImageMagick-devel-7.0.7.34-lp150.2.15.1

ImageMagick-extra-7.0.7.34-lp150.2.15.1

ImageMagick-extra-debuginfo-7.0.7.34-lp150.2.15.1

libMagick++-7_Q16HDRI4-7.0.7.34-lp150.2.15.1

libMagick++-7_Q16HDRI4-debuginfo-7.0.7.34-lp150.2.15.1

libMagick++-devel-7.0.7.34-lp150.2.15.1

libMagickCore-7_Q16HDRI6-7.0.7.34-lp150.2.15.1

libMagickCore-7_Q16HDRI6-debuginfo-7.0.7.34-lp150.2.15.1

libMagickWand-7_Q16HDRI6-7.0.7.34-lp150.2.15.1

libMagickWand-7_Q16HDRI6-debuginfo-7.0.7.34-lp150.2.15.1

perl-PerlMagick-7.0.7.34-lp150.2.15.1

perl-PerlMagick-debuginfo-7.0.7.34-lp150.2.15.1

- openSUSE Leap 15.0 (noarch):

ImageMagick-doc-7.0.7.34-lp150.2.15.1

- openSUSE Leap 15.0 (x86_64):

ImageMagick-devel-32bit-7.0.7.34-lp150.2.15.1

libMagick++-7_Q16HDRI4-32bit-7.0.7.34-lp150.2.15.1

libMagick++-7_Q16HDRI4-32bit-debuginfo-7.0.7.34-lp150.2.15.1

libMagick++-devel-32bit-7.0.7.34-lp150.2...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2018-16323.html

https://www.suse.com/security/cve/CVE-2018-16328.html

https://www.suse.com/security/cve/CVE-2018-16329.html

https://www.suse.com/security/cve/CVE-2018-16413.html

https://www.suse.com/security/cve/CVE-2018-16640.html

https://www.suse.com/security/cve/CVE-2018-16641.html

https://www.suse.com/security/cve/CVE-2018-16642.html

https://www.suse.com/security/cve/CVE-2018-16643.html

https://www.suse.com/security/cve/CVE-2018-16644.html

https://www.suse.com/security/cve/CVE-2018-16645.html

https://bugzilla.suse.com/1106855

https://bugzilla.suse.com/1106857

https://bugzilla.suse.com/1106858

https://bugzilla.suse.com/1106989

https://bugzilla.suse.com/1107604

https://bugzilla.suse.com/1107609

https://bugzilla.suse.com/1107612

https://bugzilla.suse.com/1107616

https://bugzilla.suse.com/1107618

https://bugzilla.suse.com/1107619

--

Severity
low
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:3014-1
Rating: low
Affected Products: openSUSE Leap 15.0

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here