Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

SUSE: 2019:14043-1 Moderate: ImageMagick Multiple Fixes

suse
Calendar Grey May 10, 2019
Dist Suse Esm H88
SUSE Security Notification addresses several vulnerabilities in ImageMagick, carrying advisory ID SUSE-SU-2021:12345-1 and marked with moderate criticality.
An update that fixes 8 vulnerabilities is now available

Summary

This update for ImageMagick fixes the following issues: Security issues fixed: - CVE-2019-9956: Fixed a stack-based buffer overflow in PopHexPixel() (bsc#1130330). - CVE-2019-10650: Fixed a heap-based buffer over-read in WriteTIFFImage() (bsc#1131317). - CVE-2019-11007: Fixed a heap-based buffer overflow in ReadMNGImage() (bsc#1132060). - CVE-2019-11009: Fixed a heap-based buffer over-read in ReadXWDImage() (bsc#1132053). - CVE-2019-11472: Fixed a denial-of-service in ReadXWDImage() (bsc#1133204). - CVE-2019-11470: Fixed a denial-of-service in ReadCINImage() (bsc#1133205). - CVE-2019-11506: Fixed a heap-based buffer overflow in the WriteMATLABImage() (bsc#1133498). - CVE-2019-11505: Fixed a heap-based buffer overflow in the WritePDBImage() (bsc#1133501). Patch Instructions:

References

#1130330 #1131317 #1132053 #1132060 #1133204

#1133205 #1133498 #1133501

Cross- CVE-2019-10650 CVE-2019-11007 CVE-2019-11009

CVE-2019-11470 CVE-2019-11472 CVE-2019-11505

CVE-2019-11506 CVE-2019-9956

Affected Products:

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2019-10650.html

https://www.suse.com/security/cve/CVE-2019-11007.html

https://www.suse.com/security/cve/CVE-2019-11009.html

https://www.suse.com/security/cve/CVE-2019-11470.html

https://www.suse.com/security/cve/CVE-2019-11472.html

https://www.suse.com/security/cve/CVE-2019-11505.html

https://www.suse.com/security/cve/CVE-2019-11506.html

https://www.suse.com/security/cve/CVE-2019-9956.html

https://bugzilla.suse.com/1130330

Announcement ID: SUSE-SU-2019:14043-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here