MGASA-2019-0033
Dashboard / Vulnerabilities / MGASA-2019-0033
MGASA-2019-0033
Summary: Updated graphicsmagick packages fix security vulnerabilities
Details: It was discovered that graphicsmagick was subject to vulnerabilities. * heap-based buffer overflow in the WriteTGAImage function of tga.c (CVE-2018-20184). * denial of service vulnerability in ReadDIBImage function of coders/dib.c (CVE-2018-20189). * heap-based buffer over-read in the ReadBMPImage function of bmp.c (CVE-2018-20185).
References: https://advisories.mageia.org/MGASA-2019-0033.html, https://bugs.mageia.org/show_bug.cgi?id=24103, https://lists.opensuse.org/opensuse-updates/2018-12/msg00148.html, http://lists.suse.com/pipermail/sle-security-updates/2019-January/005014.html
Affected packages
Package
Name: graphicsmagick
Purl: pkg:rpm/mageia/graphicsmagick?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
