* bsc#1241658 * bsc#1241659 Cross-References: * CVE-2025-43965 . # Security update for ImageMagick Announcement ID: SUSE-SU-2025:1464-1 Release Date: 2025-05-05T18:49:06Z Rating: moderate References: * bsc#1241658 * bsc#1241659 Cross-References: * CVE-2025-43965 * CVE-2025-46393 CVSS scores: * CVE-2025-43965 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2025-43965 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2025-43965 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-46393 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2025-46393 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2025-46393 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Desktop Applications Module 15-SP6 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for ImageMagick fixes the following issues: * CVE-2025-43965: Fixed mishandling of image depth after SetQuantumFormat is used in MIFF image processing. (bsc#1241659) * CVE-2025-46393: Fixed mishandling of packet_size leads to rendering of channels in arbitrary order in multispectral MIFF image processing. (bsc#1241658) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-1464=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2025-1464=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) *perl-PerlMagick-debuginfo-7.1.0.9-150400.6.30.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.30.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.30.1 * ImageMagick-debugsource-7.1.0.9-150400.6.30.1 * ImageMagick-devel-7.1.0.9-150400.6.30.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.30.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.30.1 * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.30.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.30.1 * ImageMagick-7.1.0.9-150400.6.30.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.30.1 * ImageMagick-extra-7.1.0.9-150400.6.30.1 * ImageMagick-extra-debuginfo-7.1.0.9-150400.6.30.1 * libMagick++-devel-7.1.0.9-150400.6.30.1 * perl-PerlMagick-7.1.0.9-150400.6.30.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.30.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.30.1 * openSUSE Leap 15.4 (x86_64) * ImageMagick-devel-32bit-7.1.0.9-150400.6.30.1 * libMagick++-devel-32bit-7.1.0.9-150400.6.30.1 * libMagickWand-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.30.1 * libMagick++-7_Q16HDRI5-32bit-debuginfo-7.1.0.9-150400.6.30.1 * libMagick++-7_Q16HDRI5-32bit-7.1.0.9-150400.6.30.1 * libMagickCore-7_Q16HDRI10-32bit-7.1.0.9-150400.6.30.1 * libMagickCore-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.30.1 * libMagickWand-7_Q16HDRI10-32bit-7.1.0.9-150400.6.30.1 * openSUSE Leap 15.4 (noarch) * ImageMagick-doc-7.1.0.9-150400.6.30.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libMagick++-7_Q16HDRI5-64bit-7.1.0.9-150400.6.30.1 * libMagick++-devel-64bit-7.1.0.9-150400.6.30.1 * libMagick++-7_Q16HDRI5-64bit-debuginfo-7.1.0.9-150400.6.30.1 * libMagickWand-7_Q16HDRI10-64bit-7.1.0.9-150400.6.30.1 * libMagickWand-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.30.1 * libMagickCore-7_Q16HDRI10-64bit-7.1.0.9-150400.6.30.1 * libMagickCore-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.30.1 * ImageMagick-devel-64bit-7.1.0.9-150400.6.30.1 * Desktop Applications Module15-SP6 (aarch64 ppc64le s390x x86_64) * ImageMagick-debuginfo-7.1.0.9-150400.6.30.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.30.1 * ImageMagick-debugsource-7.1.0.9-150400.6.30.1 ## References: * https://www.suse.com/security/cve/CVE-2025-43965.html * https://www.suse.com/security/cve/CVE-2025-46393.html * https://bugzilla.suse.com/show_bug.cgi?id=1241658 * https://bugzilla.suse.com/show_bug.cgi?id=1241659 . The recent ImageMagick patch addresses specific vulnerabilities, improving protection for SUSE users facing moderate risk.. ImageMagick Security, SUSE Update, Moderate Threat Fix. . LinuxSecurity.com Team
Update to 2.36.3: * Support capturing already encoded video streams, which takes advantage of encoding done in hardware by devices which support this feature. * Avoid using experimental GStreamer elements for video demuxing. * Avoid using the legacy GStreamer VA-API decoding plug-ins, which often cause rendering issues and are not much maintained. Their usage can be re-enabled. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-c05acca28d 2022-06-18 01:44:47.919366 --------------------------------------------------------------------------------Name : webkit2gtk3 Product : Fedora 35 Version : 2.36.3 Release : 1.fc35 URL : https://www.webkitgtk.org/ Summary : GTK Web content engine library Description : WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. This package contains WebKit2 based WebKitGTK for GTK 3. --------------------------------------------------------------------------------Update Information: Update to 2.36.3: * Support capturing already encoded video streams, which takes advantage of encoding done in hardware by devices which support this feature. * Avoid using experimental GStreamer elements for video demuxing. * Avoid using the legacy GStreamer VA-API decoding plug-ins, which often cause rendering issues and are not much maintained. Their usage can be re-enabled setting WEBKIT_GST_ENABLE_LEGACY_VAAPI=1 in the environment. * Fix playback of YouTube streams which use dynamic ad insertion. * Fix display capture with Pipewire. * Fix several crashes and rendering issues. --------------------------------------------------------------------------------ChangeLog: * Thu Jun 2 2022 Michael Catanzaro 2.36.3-1 - Update to 3.36.3 * Wed May 18 2022 Michael Catanzaro 2.36.2-1 - Update to 2.36.2 --------------------------------------------------------------------------------References: [ 1 ] Bug #2092732 - CVE-2022-26700webkitgtk: Processing maliciously crafted web content may lead to code execution https://bugzilla.redhat.com/show_bug.cgi?id=2092732 [ 2 ] Bug #2092733 - CVE-2022-26709 webkitgtk: Processing maliciously crafted web content may lead to use-after-free issue https://bugzilla.redhat.com/show_bug.cgi?id=2092733 [ 3 ] Bug #2092734 - CVE-2022-26716 webkitgtk: Processing maliciously crafted web content may lead to memory corruption https://bugzilla.redhat.com/show_bug.cgi?id=2092734 [ 4 ] Bug #2092735 - CVE-2022-26717 webkitgtk: Processing maliciously crafted web content may lead to use after free issue https://bugzilla.redhat.com/show_bug.cgi?id=2092735 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-c05acca28d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- Updated to new upstream (69.0.1) - Wayland rendering fixes ---- - The update to 69.0.1 - Fix flickering issues - Fix disappearing webrtc dialogs ---- - Fixed rendering artifacts on Wayland backend. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-7f7bace5b4 2019-09-21 00:00:44.539947 --------------------------------------------------------------------------------Name : firefox Product : Fedora 31 Version : 69.0.1 Release : 3.fc31 URL : https://www.firefox.com/en-US/?redirect_source=mozilla-org Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. --------------------------------------------------------------------------------Update Information: - Updated to new upstream (69.0.1) - Wayland rendering fixes ---- - The update to 69.0.1 - Fix flickering issues - Fix disappearing webrtc dialogs ---- -Fixed rendering artifacts on Wayland backend --------------------------------------------------------------------------------References: [ 1 ] Bug #1748442 - Firefox 69.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1748442 [ 2 ] Bug #1751372 - [Wayland] [regression] After updating to version 69, switching between tabs doesn't always update the window's contents https://bugzilla.redhat.com/show_bug.cgi?id=1751372 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-7f7bace5b4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
This update together with the previous release brings the following fixes * Security fixes: CVE-2016-1726 * Limit the number of tiles according to the visible area. This was causing a huge memory consumption with some websites. * Fix rendering of form controls and scrollbars with GTK+ > = 3.19. * Fix HTTP authentication dialog rendering when accelerated compositing mode is enabled. *. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-7eb48a78dc 2016-03-22 15:54:44.506458 -------------------------------------------------------------------------------- Name : webkitgtk4 Product : Fedora 23 Version : 2.10.9 Release : 1.fc23 URL : https://www.webkitgtk.org/ Summary : GTK+ Web content engine library Description : WebKitGTK+ is the port of the portable web rendering engine WebKit to the GTK+ platform. This package contains WebKitGTK+ for GTK+ 3. -------------------------------------------------------------------------------- Update Information: This update together with the previous release brings the following fixes * Security fixes: CVE-2016-1726 * Limit the number of tiles according to the visible area. This was causing a huge memory consumption with some websites. * Fix rendering of form controls and scrollbars with GTK+ > = 3.19. * Fix HTTP authentication dialog rendering when accelerated compositing mode is enabled. * Fix rendering artifacts when using a web view background color. * Fix a crash when creating a WebKitWebView without providing a WebKitWebContext. * Fix the build with musl libc library. * Fix the build with clang-3.8. * Fix several crashes and rendering issues. -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update webkitgtk4' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. Moredetails on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Updated poppler packages that fix multiple security issues are now available for Red Hat Enterprise Linux 5. This update has been rated as having important security impact by the Red Hat Security Response Team.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: poppler security update Advisory ID: RHSA-2009:0480-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2009:0480.html Issue date: 2009-05-13 CVE Names: CVE-2009-0146 CVE-2009-0147 CVE-2009-0166 CVE-2009-0195 CVE-2009-0799 CVE-2009-0800 CVE-2009-1179 CVE-2009-1180 CVE-2009-1181 CVE-2009-1182 CVE-2009-1183 CVE-2009-1187 CVE-2009-1188 ==================================================================== 1. Summary: Updated poppler packages that fix multiple security issues are now available for Red Hat Enterprise Linux 5. This update has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 3. Description: Poppler is a Portable Document Format (PDF) rendering library, used by applications such as Evince. Multiple integer overflow flaws were found in poppler. An attacker could create a malicious PDF file that would cause applications that use poppler (such as Evince) to crash or, potentially, execute arbitrary code when opened. (CVE-2009-0147, CVE-2009-1179, CVE-2009-1187, CVE-2009-1188) Multiple buffer overflow flaws were found in poppler's JBIG2 decoder. An attacker could create a malicious PDF file that would cause applications that use poppler (such as Evince) to crash or, potentially, execute arbitrarycode when opened. (CVE-2009-0146, CVE-2009-1182) Multiple flaws were found in poppler's JBIG2 decoder that could lead to the freeing of arbitrary memory. An attacker could create a malicious PDF file that would cause applications that use poppler (such as Evince) to crash or, potentially, execute arbitrary code when opened. (CVE-2009-0166, CVE-2009-1180) Multiple input validation flaws were found in poppler's JBIG2 decoder. An attacker could create a malicious PDF file that would cause applications that use poppler (such as Evince) to crash or, potentially, execute arbitrary code when opened. (CVE-2009-0800) Multiple denial of service flaws were found in poppler's JBIG2 decoder. An attacker could create a malicious PDF file that would cause applications that use poppler (such as Evince) to crash when opened. (CVE-2009-0799, CVE-2009-1181, CVE-2009-1183) Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product Security team, and Will Dormann of the CERT/CC for responsibly reporting these flaws. Users are advised to upgrade to these updated packages, which contain backported patches to resolve these issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 490612 - CVE-2009-0146 xpdf: Multiple buffer overflows in JBIG2 decoder (setBitmap, readSymbolDictSeg) (CVE-2009-0195) 490614 - CVE-2009-0147 xpdf: Multiple integer overflows in JBIG2 decoder 490625 - CVE-2009-0166 xpdf: Freeing of potentially uninitialized memory in JBIG2 decoder 495886 - CVE-2009-0799 PDF JBIG2 decoder OOB read 495887 - CVE-2009-0800 PDF JBIG2 multiple input validation flaws 495889 - CVE-2009-1179 PDF JBIG2 integer overflow 495892 - CVE-2009-1180 PDF JBIG2 invalid free() 495894 - CVE-2009-1181 PDF JBIG2 NULL dereference 495896 - CVE-2009-1182 PDF JBIG2 MMR decoderbuffer overflows 495899 - CVE-2009-1183 PDF JBIG2 MMR infinite loop DoS 495906 - CVE-2009-1187 poppler CairoOutputDev integer overflow 495907 - CVE-2009-1188 poppler SplashBitmap integer overflow 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: poppler-0.5.4-4.4.el5_3.9.i386.rpm poppler-debuginfo-0.5.4-4.4.el5_3.9.i386.rpm poppler-utils-0.5.4-4.4.el5_3.9.i386.rpm x86_64: poppler-0.5.4-4.4.el5_3.9.i386.rpm poppler-0.5.4-4.4.el5_3.9.x86_64.rpm poppler-debuginfo-0.5.4-4.4.el5_3.9.i386.rpm poppler-debuginfo-0.5.4-4.4.el5_3.9.x86_64.rpm poppler-utils-0.5.4-4.4.el5_3.9.x86_64.rpm RHEL Desktop Workstation (v. 5 client): Source: i386: poppler-debuginfo-0.5.4-4.4.el5_3.9.i386.rpm poppler-devel-0.5.4-4.4.el5_3.9.i386.rpm x86_64: poppler-debuginfo-0.5.4-4.4.el5_3.9.i386.rpm poppler-debuginfo-0.5.4-4.4.el5_3.9.x86_64.rpm poppler-devel-0.5.4-4.4.el5_3.9.i386.rpm poppler-devel-0.5.4-4.4.el5_3.9.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: poppler-0.5.4-4.4.el5_3.9.i386.rpm poppler-debuginfo-0.5.4-4.4.el5_3.9.i386.rpm poppler-devel-0.5.4-4.4.el5_3.9.i386.rpm poppler-utils-0.5.4-4.4.el5_3.9.i386.rpm ia64: poppler-0.5.4-4.4.el5_3.9.ia64.rpm poppler-debuginfo-0.5.4-4.4.el5_3.9.ia64.rpm poppler-devel-0.5.4-4.4.el5_3.9.ia64.rpm poppler-utils-0.5.4-4.4.el5_3.9.ia64.rpm ppc: poppler-0.5.4-4.4.el5_3.9.ppc.rpm poppler-0.5.4-4.4.el5_3.9.ppc64.rpm poppler-debuginfo-0.5.4-4.4.el5_3.9.ppc.rpm poppler-debuginfo-0.5.4-4.4.el5_3.9.ppc64.rpm poppler-devel-0.5.4-4.4.el5_3.9.ppc.rpm poppler-devel-0.5.4-4.4.el5_3.9.ppc64.rpm poppler-utils-0.5.4-4.4.el5_3.9.ppc.rpm s390x: poppler-0.5.4-4.4.el5_3.9.s390.rpm poppler-0.5.4-4.4.el5_3.9.s390x.rpm poppler-debuginfo-0.5.4-4.4.el5_3.9.s390.rpm poppler-debuginfo-0.5.4-4.4.el5_3.9.s390x.rpm poppler-devel-0.5.4-4.4.el5_3.9.s390.rpm poppler-devel-0.5.4-4.4.el5_3.9.s390x.rpm poppler-utils-0.5.4-4.4.el5_3.9.s390x.rpm x86_64: poppler-0.5.4-4.4.el5_3.9.i386.rpm poppler-0.5.4-4.4.el5_3.9.x86_64.rpm poppler-debuginfo-0.5.4-4.4.el5_3.9.i386.rpm poppler-debuginfo-0.5.4-4.4.el5_3.9.x86_64.rpm poppler-devel-0.5.4-4.4.el5_3.9.i386.rpm poppler-devel-0.5.4-4.4.el5_3.9.x86_64.rpm poppler-utils-0.5.4-4.4.el5_3.9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7.References: https://www.cve.org/CVERecord?id=CVE-2009-0146 https://www.cve.org/CVERecord?id=CVE-2009-0147 https://www.cve.org/CVERecord?id=CVE-2009-0166 https://www.cve.org/CVERecord?id=CVE-2009-0195 https://www.cve.org/CVERecord?id=CVE-2009-0799 https://www.cve.org/CVERecord?id=CVE-2009-0800 https://www.cve.org/CVERecord?id=CVE-2009-1179 https://www.cve.org/CVERecord?id=CVE-2009-1180 https://www.cve.org/CVERecord?id=CVE-2009-1181 https://www.cve.org/CVERecord?id=CVE-2009-1182 https://www.cve.org/CVERecord?id=CVE-2009-1183 https://www.cve.org/CVERecord?id=CVE-2009-1187 https://www.cve.org/CVERecord?id=CVE-2009-1188 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2009 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFKCtsFXlSAg2UNWIIRAgEzAJ9kGaBk+IAnK9EoBWyH5WFv3eNYBwCeOFYN HIYILtLAfYsCVyuSalNlhl4=9xxA -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Get the latest Linux and open source security news straight to your inbox.