Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

openSUSE: 2020:0429-1 Moderate: GraphicsMagick Integer Overflow Threat

opensuse
Calendar Grey March 31, 2020
Dist Opensuse Esm H88
The recent GraphicsMagick update in openSUSE addresses several critical vulnerabilities, specifically targeting file input handling and potential buffer overflow risks.
An update that fixes two vulnerabilities is now available.

Description

This update for GraphicsMagick fixes the following issues:

- CVE-2019-12921: Fixed an issue where text filename components

potentially coulf have allowed reading of arbitrary files via

TranslateTextEx (boo#1167208).

- CVE-2020-10938: Fixed an integer overflow and resultant heap-based

buffer overflow in HuffmanDecodeImages (boo#1167623).

This update was imported from the openSUSE:Leap:15.1:Update update project.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP1:

zypper in -t patch openSUSE-2020-429=1

Package List

- openSUSE Backports SLE-15-SP1 (x86_64):

GraphicsMagick-1.3.29-bp151.5.12.1

GraphicsMagick-devel-1.3.29-bp151.5.12.1

libGraphicsMagick++-Q16-12-1.3.29-bp151.5.12.1

libGraphicsMagick++-devel-1.3.29-bp151.5.12.1

libGraphicsMagick-Q16-3-1.3.29-bp151.5.12.1

libGraphicsMagick3-config-1.3.29-bp151.5.12.1

libGraphicsMagickWand-Q16-2-1.3.29-bp151.5.12.1

perl-GraphicsMagick-1.3.29-bp151.5.12.1

References

https://www.suse.com/security/cve/CVE-2019-12921.html

https://www.suse.com/security/cve/CVE-2020-10938.html

https://bugzilla.suse.com/1167208

https://bugzilla.suse.com/1167623

--

Announcement ID: openSUSE-SU-2020:0429-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here