CLSA-2022-1648142109
Dashboard / Vulnerabilities / CLSA-2022-1648142109
CLSA-2022-1648142109
Summary: Fix CVE(s): CVE-2020-27762, CVE-2020-27770, CVE-2020-27760, CVE-2020-25665, CVE-2020-19667, CVE-2020-25674, CVE-2017-13144, CVE-2020-25676, CVE-2020-25664, CVE-2020-27753, CVE-2020-27750
Details: * SECURITY UPDATE: Crash if image dimensions are too large - debian/patches/CVE-2017-13144-*.patch: Fix memory leak in MPC image format - CVE-2017-13144 * SECURITY UPDATE: Stack-based buffer overflow - debian/patches/CVE-2020-19667.patch: Zero-out memory before use - CVE-2020-19667 * SECURITY UPDATE: Heap-based buffer overflow - debian/patches/CVE-2020-25664.patch: Expand virtual memory allocation by 256 bytes - CVE-2020-25664 * SECURITY UPDATE: Heap-based buffer overflow - debian/patches/CVE-2020-25665.patch: Expand virtual memory allocation by 256 bytes - CVE-2020-25665 * SECURITY UPDATE: Heap-based buffer overflow - debian/patches/CVE-2020-25674.patch: Properly calculate upper limit for color loop - CVE-2020-25674 * SECURITY UPDATE: Signed integer overflows - debian/patches/CVE-2020-25676.patch: Constrain pixel offsets in magick/pixel.c - CVE-2020-25676 * SECURITY UPDATE: Division by zero - debian/patches/CVE-2020-27750.patch: Replace division by multiplication in magick/colorspace-private.h - CVE-2020-27750 * SECURITY UPDATE: Memory leaks - debian/patches/CVE-2020-27753.patch: Fix memory handling in coders/miff.c - CVE-2020-27753 * SECURITY UPDATE: Division by zero - debian/patches/CVE-2020-27760.patch: Fix division by zeros in magick/enhance.c - CVE-2020-27760 * SECURITY UPDATE: Outside the range of representable values - debian/patches/CVE-2020-27762.patch: Adds consistency checks in coders/hdr.c - CVE-2020-27762 * SECURITY UPDATE: Unsigned int overflow - debian/patches/CVE-2020-27770.patch: Guard against underflow when decrement value in magick/string.c - CVE-2020-27770
Affected packages
Package
Name: imagemagick
Purl: pkg:deb/tuxcare/imagemagick?distro=ubuntu-16.04
Affected ranges
Type: ECOSYSTEM
Events:
