security advisorysecurity issuebug report
GraphicsMagick 1.3.32 is now released, fixing another 52 additional issues detected by oss-fuzz. Of special mention is a bug reported to us by "Battle Furry" via our security mail alias. This bug (was considered to be a "feature") . MGASA-2019-0194 - Updated graphicsmagick packages fix security vulnerabilities Publication date: 21 Jun 2019 URL: https://advisories.mageia.org/MGASA-2019-0194.html Type: security Affected Mageia releases: 6 GraphicsMagick 1.3.32 is now released, fixing another 52 additional issues detected by oss-fuzz. Of special mention is a bug reported to us by "Battle Furry" via our security mail alias. This bug (was considered to be a "feature") allows including file text as rendered text on a graphic image, or as text hidden in metadata, by using a file refered to with This email address is being protected from spambots. You need JavaScript enabled to view it.' syntax where text to be rendered normally appears. This issue was inherited from ImageMagick 5.5.2 and it even appears in ImageMagick 4.2.9. It has been determined that the SVG and WMF formats may be used to supply this This email address is being protected from spambots. You need JavaScript enabled to view it.' syntax, resulting in rendered text on a graphic image, or as text hidden in metadata (e.g. the image comment). Furthermore, it may be that other applications and web sites accept text to be rendered on behalf of users and that this issue could allow untrusted users to receive content considered to be secure and private (e.g. private keys or passwords). References: - https://bugs.mageia.org/show_bug.cgi?id=24966 - https://www.openwall.com/lists/oss-security/2019/06/15/9 SRPMS: - 6/core/graphicsmagick-1.3.32-1.mga6 . GraphicsMagick version 1.3.32 introduces a security update that resolves 52 vulnerabilities uncovered by oss-fuzz, significantly improving the security posture of Mageia 6.. GraphicsMagick Security, Mageia Update, OSS-Fuzz Issues, Security Fixes, GraphicsMagick Bug Report. . LinuxSecurity.com Team
Jun 20, 2019
Mageia