Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

SUSE: 2016:3258-1 Important: ImageMagick Heap Overflow and Execution Risk

suse
Calendar Grey December 23, 2016
Dist Suse Esm H88
Tackling 6 critical issues in ImageMagick for SUSE clients. Security patch released promptly for your protection.
An update that fixes 6 vulnerabilities is now available

Summary

This update for ImageMagick fixes the following issues: * CVE-2016-9556 Possible Heap-overflow found by fuzzing [bsc#1011130] * CVE-2016-9559 Possible Null pointer access found by fuzzing [bsc#1011136] * CVE-2016-8707 Possible code execution in Tiff conver utility [bsc#1014159] * CVE-2016-8866 Memory allocation failure in AcquireMagickMemory could lead to Heap overflow [bsc#1009318] * CVE-2016-9559 Possible Null pointer access found by fuzzing [bsc#1011136] Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP2: zypper in -t patch SUSE-SLE-WE-12-SP2-2016-1905=1 - SUSE Linux Enterprise Workstation Extension 12-SP1:

References

#1009318 #1011130 #1011136 #1013376 #1014159

Cross- CVE-2014-9848 CVE-2016-8707 CVE-2016-8866

CVE-2016-9556 CVE-2016-9559 CVE-2016-9773

Affected Products:

SUSE Linux Enterprise Workstation Extension 12-SP2

SUSE Linux Enterprise Workstation Extension 12-SP1

SUSE Linux Enterprise Software Development Kit 12-SP2

SUSE Linux Enterprise Software Development Kit 12-SP1

SUSE Linux Enterprise Server for Raspberry Pi 12-SP2

SUSE Linux Enterprise Server 12-SP2

SUSE Linux Enterprise Server 12-SP1

SUSE Linux Enterprise Desktop 12-SP2

SUSE Linux Enterprise Desktop 12-SP1

https://www.suse.com/security/cve/CVE-2014-9848.html

https://www.suse.com/security/cve/CVE-2016-8707.html

https://www.suse.com/security/cve/CVE-2016-8866.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:3258-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here