Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

SUSE: 2021:1276-1 Moderate: ImageMagick Application Issue Fix

suse
Calendar Grey April 20, 2021
Scroller Suse
ImageMagick has implemented a critical SUSE security update that resolves multiple vulnerabilities. Ensure your system is secure by applying these updates promptly.
An update that fixes four vulnerabilities is now available

Summary

This update for ImageMagick fixes the following issues: - CVE-2021-20309: Division by zero in WaveImage() of MagickCore/visual-effects. (bsc#1184624) - CVE-2021-20311: Division by zero in sRGBTransformImage() in MagickCore/colorspace.c (bsc#1184626) - CVE-2021-20312: Integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c (bsc#1184627) - CVE-2021-20313: Cipher leak when the calculating signatures in TransformSignatureof MagickCore/signature.c (bsc#1184628) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Development Tools 15-SP3:

References

#1184624 #1184626 #1184627 #1184628

Cross- CVE-2021-20309 CVE-2021-20311 CVE-2021-20312

CVE-2021-20313

CVSS scores:

CVE-2021-20309 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CVE-2021-20311 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CVE-2021-20312 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CVE-2021-20313 (SUSE): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected Products:

SUSE Linux Enterprise Module for Development Tools 15-SP3

SUSE Linux Enterprise Module for Development Tools 15-SP2

SUSE Linux Enterprise Module for Desktop Applications 15-SP3

SUSE Linux Enterprise Module for Desktop Applications 15-SP2

https://www.suse.com/security/cve/CVE-2021-20309.html

Announcement ID: SUSE-SU-2021:1276-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.