Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

openSUSE Leap 42.3: 2018:3240-3 - Critical ImageMagick Buffer Issue

opensuse
Calendar Grey October 18, 2018
Dist Opensuse Esm H88
Important security patch resolves various vulnerabilities in ImageMagick for openSUSE, bolstering system defenses.
An update that fixes 7 vulnerabilities is now available.

Description

This update for ImageMagick fixes the following issues:

Security issues fixed:

- CVE-2018-18024: Fixed an infinite loop in the ReadBMPImage function of

the coders/bmp.c file. Remote attackers could leverage this

vulnerability to cause a denial of service via a crafted bmp file.

(bsc#1111069)

- CVE-2018-18016: Fixed a memory leak in WritePCXImage (bsc#1111072).

- CVE-2018-17965: Fixed a memory leak in WriteSGIImage (bsc#1110747).

- CVE-2018-17966: Fixed a memory leak in WritePDBImage (bsc#1110746).

- CVE-2018-12600: ReadDIBImage and WriteDIBImage allowed attackers to

cause an out of bounds write via a crafted file. (bsc#1098545)

- CVE-2018-12599: ReadBMPImage and WriteBMPImage allowed attackers to

cause an out of bounds write via a crafted file. (bsc#1098546)

This update was imported from the SUSE:SLE-12:Update update project.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-1197=1

Package List

- openSUSE Leap 42.3 (i586 x86_64):

ImageMagick-6.8.8.1-73.1

ImageMagick-debuginfo-6.8.8.1-73.1

ImageMagick-debugsource-6.8.8.1-73.1

ImageMagick-devel-6.8.8.1-73.1

ImageMagick-extra-6.8.8.1-73.1

ImageMagick-extra-debuginfo-6.8.8.1-73.1

libMagick++-6_Q16-3-6.8.8.1-73.1

libMagick++-6_Q16-3-debuginfo-6.8.8.1-73.1

libMagick++-devel-6.8.8.1-73.1

libMagickCore-6_Q16-1-6.8.8.1-73.1

libMagickCore-6_Q16-1-debuginfo-6.8.8.1-73.1

libMagickWand-6_Q16-1-6.8.8.1-73.1

libMagickWand-6_Q16-1-debuginfo-6.8.8.1-73.1

perl-PerlMagick-6.8.8.1-73.1

perl-PerlMagick-debuginfo-6.8.8.1-73.1

- openSUSE Leap 42.3 (x86_64):

ImageMagick-devel-32bit-6.8.8.1-73.1

libMagick++-6_Q16-3-32bit-6.8.8.1-73.1

libMagick++-6_Q16-3-debuginfo-32bit-6.8.8.1-73.1

libMagick++-devel-32bit-6.8.8.1-73.1

libMagickCore-6_Q16-1-32bit-6.8.8.1-73.1

libMagickCore-6_Q16-1-debuginfo-32bit-6.8.8.1-73.1

libMagickWand-6_Q16-1-32bit-6.8.8.1-73.1

libMagickWand-6_Q16-1-debuginfo-32bit-6.8.8.1-73.1

- openSUSE Leap 42.3 (noarch):

ImageMagick-doc-6.8.8.1-73.1

References

https://www.suse.com/security/cve/CVE-2017-13058.html

https://www.suse.com/security/cve/CVE-2018-12599.html

https://www.suse.com/security/cve/CVE-2018-12600.html

https://www.suse.com/security/cve/CVE-2018-17965.html

https://www.suse.com/security/cve/CVE-2018-17966.html

https://www.suse.com/security/cve/CVE-2018-18016.html

https://www.suse.com/security/cve/CVE-2018-18024.html

https://bugzilla.suse.com/1098545

https://bugzilla.suse.com/1098546

https://bugzilla.suse.com/1110746

https://bugzilla.suse.com/1110747

https://bugzilla.suse.com/1111069

https://bugzilla.suse.com/1111072

--

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:3225-1
Rating: moderate
Affected Products: openSUSE Leap 42.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here