Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

openSUSE Leap 15.1: 2020:0014-1 Moderate: php7-imagick Security Issue

opensuse
Calendar Grey January 13, 2020
Dist Opensuse Esm H88
The php7-xmlrpc update resolves a significant security vulnerability, addressing various bugs while enhancing efficiency.
An update that fixes one vulnerability is now available.

Description

This update for php7-imagick fixes the following issues:

Upgrade to version 3.4.4:

Added:

* function Imagick::optimizeImageTransparency()

* METRIC_STRUCTURAL_SIMILARITY_ERROR

* METRIC_STRUCTURAL_DISSIMILARITY_ERROR

* COMPRESSION_ZSTD - https://github.com/facebook/zstd

* COMPRESSION_WEBP

* CHANNEL_COMPOSITE_MASK

* FILTER_CUBIC_SPLINE - "Define the lobes with the -define

filter:lobes={2,3,4} (reference

;t=32506)."

* Imagick now explicitly conflicts with the Gmagick extension.

Fixes:

* Correct version check to make RemoveAlphaChannel and

FlattenAlphaChannel be available when using Imagick with ImageMagick

version 6.7.8-x

* Bug 77128 - Imagick::setImageInterpolateMethod() not available on

Windows

* Prevent memory leak when ImagickPixel::__construct called after object

instantiation.

* Prevent segfault when ImagickPixel internal constructor not called.

*...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-14=1

- openSUSE Backports SLE-15-SP1:

zypper in -t patch openSUSE-2020-14=1

Package List

- openSUSE Leap 15.1 (x86_64):

php7-imagick-3.4.4-lp151.8.3.1

php7-imagick-debuginfo-3.4.4-lp151.8.3.1

php7-imagick-debugsource-3.4.4-lp151.8.3.1

- openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64):

php7-imagick-3.4.4-bp151.2.3.1

References

https://www.suse.com/security/cve/CVE-2019-11037.html

https://bugzilla.suse.com/1135418

--

Announcement ID: openSUSE-SU-2020:0014-1
Rating: moderate
Affected Products: openSUSE Leap 15.1 openSUSE Backports SLE-15-SP1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here