Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE: 2019:1523-1 Moderate: ImageMagick DoS And Buffer Overflow Fix

suse
Calendar Grey June 17, 2019
Dist Suse Esm H88
New version of ImageMagick released, correcting several vulnerabilities such as denial-of-service attacks and buffer overflows.
An update that solves 5 vulnerabilities and has one errata is now available

Summary

This update for ImageMagick fixes the following issues: Security issues fixed: - CVE-2019-11472: Fixed a denial-of-service in ReadXWDImage() (bsc#1133204). - CVE-2019-11470: Fixed a denial-of-service in ReadCINImage() (bsc#1133205). - CVE-2019-11506: Fixed a heap-based buffer overflow in the WriteMATLABImage() (bsc#1133498). - CVE-2019-11505: Fixed a heap-based buffer overflow in the WritePDBImage() (bsc#1133501). - CVE-2019-11598: Fixed a heap-based buffer overread in WritePNMImage() (bsc#1136732) We also now disable PCL in the -SUSE configuration, as it also uses ghostscript for decoding (bsc#1136183) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".

References

#1133204 #1133205 #1133498 #1133501 #1136183

#1136732

Cross- CVE-2019-11470 CVE-2019-11472 CVE-2019-11505

CVE-2019-11506 CVE-2019-11598

Affected Products:

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15

SUSE Linux Enterprise Module for Development Tools 15-SP1

SUSE Linux Enterprise Module for Development Tools 15

SUSE Linux Enterprise Module for Desktop Applications 15-SP1

SUSE Linux Enterprise Module for Desktop Applications 15

https://www.suse.com/security/cve/CVE-2019-11470.html

https://www.suse.com/security/cve/CVE-2019-11472.html

https://www.suse.com/security/cve/CVE-2019-11505.html

https://www.suse.com/security/cve/CVE-2019-11506.html

Announcement ID: SUSE-SU-2019:1523-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here