CLSA-2022-1654802345
Dashboard / Vulnerabilities / CLSA-2022-1654802345
CLSA-2022-1654802345
Summary: Fix CVE(s): CVE-2022-28463, CVE-2020-27760
Details: * SECURITY UPDATE: Division by zero - debian/patches/CVE-2020-27760.patch: Fix divisions by zeros in magick/enhance.c - CVE-2020-27760 * SECURITY UPDATE: Heap-based buffer overflow - debian/patches/CVE-2022-28463.patch: Fix buffer overflow - CVE-2022-28463 * Fix several issues with undefined behavior: - debian/patches/fix-potential-divide-by-zero-in-svg.patch: Fix potential division by zero in coders/svg.c - debian/patches/fix-out-of-range-value-in-txt.patch: Fix undefined behavior in the form of values outside the range of 'unsigned long long' type in coders/text.c - debian/patches/fix-out-of-range-value-in-scale-to-quantum.patch: Fix undefined behavior in the form of values outside the range of 'unsigned short' type in magic/quantum-private.h - debian/patches/fix-shift-value-overflow-in-bmp.patch: Fix overflow on value shift in coders/bmp.c
Affected packages
Package
Name: imagemagick
Purl: pkg:deb/tuxcare/imagemagick?distro=ubuntu-16.04
Affected ranges
Type: ECOSYSTEM
Events:
