Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2020:0275-1 Moderate: ImageMagick Heap Overflow Issues

suse
Calendar Grey January 30, 2020
Dist Suse Esm H88
SUSE has rolled out a security update that mitigates moderate vulnerabilities found in ImageMagick. This update includes patches for a range of Linux modules and associated packages.
An update that solves two vulnerabilities and has one errata is now available

Summary

This update for ImageMagick fixes the following issues: Security issue fixed: - CVE-2019-19948: Fixed a heap-based buffer overflow in WriteSGIImage() (bsc#1159861). - CVE-2019-19949: Fixed a heap-based buffer over-read in WritePNGImage() (bsc#1160369). Non-security issue fixed: - Fixed an issue where converting tiff to png would lead to unviewable files (bsc#1161194). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-SP1-2020-275=1

References

#1159861 #1160369 #1161194

Cross- CVE-2019-19948 CVE-2019-19949

Affected Products:

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15

SUSE Linux Enterprise Module for Development Tools 15-SP1

SUSE Linux Enterprise Module for Development Tools 15

SUSE Linux Enterprise Module for Desktop Applications 15-SP1

SUSE Linux Enterprise Module for Desktop Applications 15

https://www.suse.com/security/cve/CVE-2019-19948.html

https://www.suse.com/security/cve/CVE-2019-19949.html

https://bugzilla.suse.com/1159861

https://bugzilla.suse.com/1160369

https://bugzilla.suse.com/1161194

Announcement ID: SUSE-SU-2020:0275-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here