Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

SUSE 11-SP4: 2016:2964-1 Important: ImageMagick Resource Threats

suse
Calendar Grey December 1, 2016
Dist Suse Esm H88
Crucial announcement for ImageMagick tackling 34 security flaws and possible resource concerns. Safeguard your SUSE platform today.
An update that fixes 34 vulnerabilities is now available

Summary

This update for ImageMagick fixes the following issues: These vulnerabilities could be triggered by processing specially crafted image files, which could lead to a process crash or resource consumtion, or potentially have unspecified futher impact. - CVE-2016-8862: Memory allocation failure in AcquireMagickMemory (bsc#1007245) - CVE-2014-9907: DOS due to corrupted DDS files (bsc#1000714) - CVE-2015-8959: DOS due to corrupted DDS files (bsc#1000713) - CVE-2016-7537: Out of bound access for corrupted pdb file (bsc#1000711) - CVE-2016-6823: BMP Coder Out-Of-Bounds Write Vulnerability (bsc#1001066) - CVE-2016-7514: Out-of-bounds read in coders/psd.c (bsc#1000688) - CVE-2016-7515: Rle file handling for corrupted file (bsc#1000689) - CVE-2016-7529: out of bound in quantum handling (bsc#1000399)

References

#1000399 #1000434 #1000436 #1000688 #1000689

#1000690 #1000691 #1000692 #1000693 #1000694

#1000695 #1000698 #1000699 #1000700 #1000701

#1000703 #1000704 #1000707 #1000709 #1000711

#1000713 #1000714 #1001066 #1001221 #1002209

#1002421 #1002422 #1003629 #1005123 #1005125

#1005127 #1007245

Cross- CVE-2014-9907 CVE-2015-8957 CVE-2015-8958

CVE-2015-8959 CVE-2016-5687 CVE-2016-6823

CVE-2016-7101 CVE-2016-7514 CVE-2016-7515

CVE-2016-7516 CVE-2016-7517 CVE-2016-7518

CVE-2016-7519 CVE-2016-7522 CVE-2016-7523

CVE-2016-7524 CVE-2016-7525 CVE-2016-7526

CVE-2016-7527 CVE-2016-7528 CVE-2016-7529

CVE-2016-7530 CVE-2016-7531 CVE-2016-7533

CVE-2016-7535 CVE-2016-7537 CVE-2016-7799

CVE-2016-7800 CVE-2016...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:2964-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here