Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

SUSE Linux Enterprise: 2018:2043-1 Moderate: ImageMagick Security Issues

suse
Calendar Grey July 23, 2018
Scroller Suse
This Red Hat security patch resolves various flaws in the libcurl library, delivering critical updates for its users.
An update that solves 5 vulnerabilities and has two fixes is now available

Summary

This update for ImageMagick fixes the following issues: The following security vulnerabilities were fixed: - CVE-2018-11625: Fixed heap-based buffer over-read in SetGrayscaleImage in the quantize.c file, which allowed remote attackers to cause buffer over-read via a crafted file. (bsc#1096200) - CVE-2018-11624: Fixed a use-after-free issue in the ReadMATImage function in coders/mat.c. (bsc#1096203) - CVE-2018-10805: Fixed several memory leaks in bgr.c, rgb.c, cmyk.c, gray.c, and ycbcr.c (bsc#1095812) - CVE-2018-12600: The ReadDIBImage and WriteDIBImage functions allowed attackers to cause an out of bounds write via a crafted file (bsc#1098545). - CVE-2018-12599: The ReadBMPImage and WriteBMPImage fucntions allowed attackers to cause an out of bounds write via a crafted file (bsc#1098546).

References

#1094742 #1094745 #1095812 #1096200 #1096203

#1098545 #1098546

Cross- CVE-2018-10805 CVE-2018-11624 CVE-2018-11625

CVE-2018-12599 CVE-2018-12600

Affected Products:

SUSE Linux Enterprise Module for Development Tools 15

SUSE Linux Enterprise Module for Desktop Applications 15

https://www.suse.com/security/cve/CVE-2018-10805.html

https://www.suse.com/security/cve/CVE-2018-11624.html

https://www.suse.com/security/cve/CVE-2018-11625.html

https://www.suse.com/security/cve/CVE-2018-12599.html

https://www.suse.com/security/cve/CVE-2018-12600.html

https://bugzilla.suse.com/1094742

https://bugzilla.suse.com/1094745

https://bugzilla.suse.com/1095812

https://bugzilla.suse.com/1096200

https://bugzilla.suse.com/1096203

Announcement ID: SUSE-SU-2018:2043-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.