MGASA-2019-0142
Dashboard / Vulnerabilities / MGASA-2019-0142
MGASA-2019-0142
Summary: Updated imagemagick packages fix security vulnerability
Details: In ImageMagick 7.0.8-36 Q16, there is a memory leak in the function SVGKeyValuePairs of coders/svg.c, which allows an attacker to cause a denial of service via a crafted image file. (CVE-2019-10649) In ImageMagick 7.0.8-36 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to cause a denial of service or information disclosure via a crafted image file. (CVE-2019-10650)
References: https://advisories.mageia.org/MGASA-2019-0142.html, https://bugs.mageia.org/show_bug.cgi?id=24614, https://www.imagemagick.org/script/changelog.php
Affected packages
Package
Name: imagemagick
Purl: pkg:rpm/mageia/imagemagick?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
