MGASA-2016-0252

    Dashboard / Vulnerabilities / MGASA-2016-0252

    MGASA-2016-0252

    Published: 14 Jul 2016Last Modified: 16 Apr 2026

    Summary: Updated graphicsmagick packages fix security vulnerability

    Details: - A read out-of-bound in the parsing of gif files using GraphicsMagick (CVE-2015-8808). - Infinite loop caused by converting a circularly defined svg file (CVE-2016-5240). - Fix another case of CVE-2016-2317 (heap buffer overflow) in the MVG rendering code (also impacts SVG). - arithmetic exception converting a svg file (CVE-2016-5241) - Arithmetic exception converting a svg file caused by a X%0 operation in magick/render.c (CVE-2016-2318) - A shell exploit (CVE-2016-5118) was discovered associated with a filename syntax where file names starting with '|' are intepreted as shell commands executed via popen(). Insufficient sanitization in the SVG and MVG renderers allows such filenames to be passed through from potentially untrusted files. There might be other ways for untrusted inputs to produce such filenames. Due to this issue, support for the feature is removed entirely. The gnudl, octave, pdf2djvu, and photoqt packages have been rebuilt to use the updated GraphicsMagick++ library.

    Affected packages

    Package

    Name: graphicsmagick

    Purl: pkg:rpm/mageia/graphicsmagick?arch=source&distro=mageia-5

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.3.24-1.2.mga5

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    MGASA-2016-0252 | CVE-DB