Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

SUSE Linux 12 SP3: 2018:2778-1 Moderate: ImageMagick Memory Leak

suse
Calendar Grey September 21, 2018
Dist Suse Esm H88
A recent security patch for ImageMagick has resolved 6 vulnerabilities deemed moderate in severity, specifically for users running SUSE Linux.
An update that solves 6 vulnerabilities and has one errata is now available

Summary

This update for ImageMagick fixes the following issues: The following security vulnerabilities were fixed: - CVE-2018-16329: Prevent NULL pointer dereference in the GetMagickProperty function leading to DoS (bsc#1106858) - CVE-2018-16323: ReadXBMImage left data uninitialized when processing an XBM file that has a negative pixel value. If the affected code was used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data (bsc#1106855) - CVE-2018-14434: Fixed a memory leak for a colormap in WriteMPCImage (bsc#1102003) - CVE-2018-14435: Fixed a memory leak in DecodeImage in coders/pcd.c (bsc#1102007) - CVE-2018-14436: Fixed a memory leak in ReadMIFFImage in coders/miff.c (bsc#1102005)

References

#1102003 #1102004 #1102005 #1102007 #1105592

#1106855 #1106858

Cross- CVE-2018-14434 CVE-2018-14435 CVE-2018-14436

CVE-2018-14437 CVE-2018-16323 CVE-2018-16329

Affected Products:

SUSE Linux Enterprise Workstation Extension 12-SP3

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Desktop 12-SP3

https://www.suse.com/security/cve/CVE-2018-14434.html

https://www.suse.com/security/cve/CVE-2018-14435.html

https://www.suse.com/security/cve/CVE-2018-14436.html

https://www.suse.com/security/cve/CVE-2018-14437.html

https://www.suse.com/security/cve/CVE-2018-16323.html

https://www.suse.com/security/cve/CVE-2018-16329.html

https://bugzilla.suse.com/1102003

Announcement ID: SUSE-SU-2018:2778-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here