Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

openSUSE Leap 15.2: 2021:0606-1 Moderate ImageMagick Security Update

opensuse
Calendar Grey April 23, 2021
Dist Opensuse Esm H88
The recent patch for ImageMagick addresses four vulnerabilities rated at moderate risk within openSUSE, enhancing the application's security and overall reliability.
An update that fixes four vulnerabilities is now available

Description

This update for ImageMagick fixes the following issues:

- CVE-2021-20309: Division by zero in WaveImage() of

MagickCore/visual-effects. (bsc#1184624)

- CVE-2021-20311: Division by zero in sRGBTransformImage() in

MagickCore/colorspace.c (bsc#1184626)

- CVE-2021-20312: Integer overflow in WriteTHUMBNAILImage of

coders/thumbnail.c (bsc#1184627)

- CVE-2021-20313: Cipher leak when the calculating signatures in

TransformSignatureof MagickCore/signature.c (bsc#1184628)

This update was imported from the SUSE:SLE-15-SP2:Update update project.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-606=1

Package List

- openSUSE Leap 15.2 (i586 x86_64):

ImageMagick-7.0.7.34-lp152.12.15.1

ImageMagick-config-7-SUSE-7.0.7.34-lp152.12.15.1

ImageMagick-config-7-upstream-7.0.7.34-lp152.12.15.1

ImageMagick-debuginfo-7.0.7.34-lp152.12.15.1

ImageMagick-debugsource-7.0.7.34-lp152.12.15.1

ImageMagick-devel-7.0.7.34-lp152.12.15.1

ImageMagick-extra-7.0.7.34-lp152.12.15.1

ImageMagick-extra-debuginfo-7.0.7.34-lp152.12.15.1

libMagick++-7_Q16HDRI4-7.0.7.34-lp152.12.15.1

libMagick++-7_Q16HDRI4-debuginfo-7.0.7.34-lp152.12.15.1

libMagick++-devel-7.0.7.34-lp152.12.15.1

libMagickCore-7_Q16HDRI6-7.0.7.34-lp152.12.15.1

libMagickCore-7_Q16HDRI6-debuginfo-7.0.7.34-lp152.12.15.1

libMagickWand-7_Q16HDRI6-7.0.7.34-lp152.12.15.1

libMagickWand-7_Q16HDRI6-debuginfo-7.0.7.34-lp152.12.15.1

perl-PerlMagick-7.0.7.34-lp152.12.15.1

perl-PerlMagick-debuginfo-7.0.7.34-lp152.12.15.1

- openSUSE Leap 15.2 (x86_64):

ImageMagick-devel-32bit-7.0.7.34-lp152.12.15.1

libMagick++-7_Q16HDRI4-32bit-7.0.7.34-lp152.12.15.1

libMagick++-7_Q16HDRI4-32bit-debuginfo-7.0.7.34-lp...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2021-20309.html

https://www.suse.com/security/cve/CVE-2021-20311.html

https://www.suse.com/security/cve/CVE-2021-20312.html

https://www.suse.com/security/cve/CVE-2021-20313.html

https://bugzilla.suse.com/1184624

https://bugzilla.suse.com/1184626

https://bugzilla.suse.com/1184627

https://bugzilla.suse.com/1184628

Announcement ID: openSUSE-SU-2021:0606-1
Rating: moderate
Affected Products: openSUSE Leap 15.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here