An update that fixes four vulnerabilities is now available. . openSUSE Security Update: Security update for ImageMagick ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0377-1 Rating: moderate References: #1182325 #1182335 #1182336 #1182337 Cross-References: CVE-2021-20241 CVE-2021-20243 CVE-2021-20244 CVE-2021-20246 CVSS scores: CVE-2021-20241 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2021-20243 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2021-20244 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2021-20246 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for ImageMagick fixes the following issues: - CVE-2021-20241 [bsc#1182335]: Division by zero in WriteJP2Image() in coders/jp2.c - CVE-2021-20243 [bsc#1182336]: Division by zero in GetResizeFilterWeight in MagickCore/resize.c - CVE-2021-20244 [bsc#1182325]: Division by zero in ImplodeImage in MagickCore/visual-effects.c - CVE-2021-20246 [bsc#1182337]: Division by zero in ScaleResampleFilter in MagickCore/resample.c This update was imported from the SUSE:SLE-15-SP2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-377=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): ImageMagick-7.0.7.34-lp152.12.12.1 ImageMagick-config-7-SUSE-7.0.7.34-lp152.12.12.1 ImageMagick-config-7-upstream-7.0.7.34-lp152.12.12.1 ImageMagick-debuginfo-7.0.7.34-lp152.12.12.1 ImageMagick-debugsource-7.0.7.34-lp152.12.12.1 ImageMagick-devel-7.0.7.34-lp152.12.12.1 ImageMagick-extra-7.0.7.34-lp152.12.12.1 ImageMagick-extra-debuginfo-7.0.7.34-lp152.12.12.1 libMagick++-7_Q16HDRI4-7.0.7.34-lp152.12.12.1 libMagick++-7_Q16HDRI4-debuginfo-7.0.7.34-lp152.12.12.1 libMagick++-devel-7.0.7.34-lp152.12.12.1 libMagickCore-7_Q16HDRI6-7.0.7.34-lp152.12.12.1 libMagickCore-7_Q16HDRI6-debuginfo-7.0.7.34-lp152.12.12.1 libMagickWand-7_Q16HDRI6-7.0.7.34-lp152.12.12.1 libMagickWand-7_Q16HDRI6-debuginfo-7.0.7.34-lp152.12.12.1 perl-PerlMagick-7.0.7.34-lp152.12.12.1 perl-PerlMagick-debuginfo-7.0.7.34-lp152.12.12.1 - openSUSE Leap 15.2 (noarch): ImageMagick-doc-7.0.7.34-lp152.12.12.1 - openSUSE Leap 15.2 (x86_64): ImageMagick-devel-32bit-7.0.7.34-lp152.12.12.1 libMagick++-7_Q16HDRI4-32bit-7.0.7.34-lp152.12.12.1 libMagick++-7_Q16HDRI4-32bit-debuginfo-7.0.7.34-lp152.12.12.1 libMagick++-devel-32bit-7.0.7.34-lp152.12.12.1 libMagickCore-7_Q16HDRI6-32bit-7.0.7.34-lp152.12.12.1 libMagickCore-7_Q16HDRI6-32bit-debuginfo-7.0.7.34-lp152.12.12.1 libMagickWand-7_Q16HDRI6-32bit-7.0.7.34-lp152.12.12.1 libMagickWand-7_Q16HDRI6-32bit-debuginfo-7.0.7.34-lp152.12.12.1 References: https://www.suse.com/security/cve/CVE-2021-20241.html https://www.suse.com/security/cve/CVE-2021-20243.html https://www.suse.com/security/cve/CVE-2021-20244.html https://www.suse.com/security/cve/CVE-2021-20246.html https://bugzilla.suse.com/1182325 https://bugzilla.suse.com/1182335 https://bugzilla.suse.com/1182336 https://bugzilla.suse.com/1182337 . Recent enhancements in GIMP have resolved several vulnerabilities affecting Fedora. Make sure your installation is updated to benefit from these vital security upgrades.. ImageMagick Update, openSUSE Security, Moderate Security Fix. .LinuxSecurity.com Team
MinGW cross compiled librsvg 2.40.18 release, fixing CVE-2017-11464 (division- by-zero in the Gaussian blur code).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-0b8c45ebf7 2017-07-28 14:18:06.095617 --------------------------------------------------------------------------------Name : mingw-librsvg2 Product : Fedora 24 Version : 2.40.18 Release : 1.fc24 URL : https://wiki.gnome.org/Projects/LibRsvg Summary : SVG library based on cairo for MinGW Description : An SVG library based on cairo for MinGW. --------------------------------------------------------------------------------Update Information: MinGW cross compiled librsvg 2.40.18 release, fixing CVE-2017-11464 (division-by-zero in the Gaussian blur code). --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade mingw-librsvg2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.