Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2020:15523-1 Moderate: ImageMagick Security Patch

suse
Calendar Grey March 29, 2019
Dist Suse Esm H88
SUSE Security Patch for ImageMagick resolves various vulnerabilities, enhancing robustness and security for affected applications.
An update that fixes four vulnerabilities is now available

Summary

This update for GraphicsMagick fixes the following issues: Security issues fixed: - CVE-2019-7175: Fixed multiple memory leaks in DecodeImage function (bsc#1128649). - CVE-2018-20467: Fixed infinite loop in coders/bmp.c (bsc#1120381) - CVE-2019-7398: Fixed a memory leak in the function WriteDIBImage (bsc#1124365). - CVE-2019-7397: Fixed a memory leak in the function WritePDFImage (bsc#1124366). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Studio Onsite 1.3: zypper in -t patch slestso13-GraphicsMagick-13995=1 - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-GraphicsMagick-13995=1

References

#1120381 #1124365 #1124366 #1128649

Cross- CVE-2018-20467 CVE-2019-7175 CVE-2019-7397

CVE-2019-7398

Affected Products:

SUSE Studio Onsite 1.3

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2018-20467.html

https://www.suse.com/security/cve/CVE-2019-7175.html

https://www.suse.com/security/cve/CVE-2019-7397.html

https://www.suse.com/security/cve/CVE-2019-7398.html

https://bugzilla.suse.com/1120381

https://bugzilla.suse.com/1124365

https://bugzilla.suse.com/1124366

https://bugzilla.suse.com/1128649

Announcement ID: SUSE-SU-2019:13995-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here