Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

SUSE: 2021:2834-1 Critical: LibXML2 Security Vulnerabilities

suse
Calendar Grey May 11, 2016
Dist Suse Esm H88
Implement solutions to address various vulnerabilities in ImageMagick for SUSE, safeguarding system reliability and protection.
An update that fixes 5 vulnerabilities is now available

Summary

This update for ImageMagick fixes the following issues: Security issues fixed: - Several coders were vulnerable to remote code execution attacks, these coders have now been disabled. They can be re-enabled by exporting the following environment variable MAGICK_CODER_MODULE_PATH=/usr/lib64/ImageMagick-6.4.3/modules-Q16/coders/vu lnerable/ (bsc#978061) - CVE-2016-3714: Insufficient shell characters filtering leads to (potentially remote) code execution - CVE-2016-3715: Possible file deletion by using ImageMagick's 'ephemeral' pseudo protocol which deletes files after reading. - CVE-2016-3716: Possible file moving by using ImageMagick's 'msl' pseudo protocol with any extension in any folder. - CVE-2016-3717: Possible local file read by using ImageMagick's 'label'

References

#978061

Cross- CVE-2016-3714 CVE-2016-3715 CVE-2016-3716

CVE-2016-3717 CVE-2016-3718

Affected Products:

SUSE OpenStack Cloud 5

SUSE Manager Proxy 2.1

SUSE Manager 2.1

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Server 11-SP2-LTSS

SUSE Linux Enterprise Debuginfo 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP2

https://www.suse.com/security/cve/CVE-2016-3714.html

https://www.suse.com/security/cve/CVE-2016-3715.html

https://www.suse.com/security/cve/CVE-2016-3716.html

https://www.suse.com/security/cve/CVE-2016-3717.html

https://www.suse.com/security/cve/CVE-2016-3718.html

https://bugzilla.suse.com/978061

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:1275-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here