SUSE-SU-2016:1614-1
Dashboard / Vulnerabilities / SUSE-SU-2016:1614-1
SUSE-SU-2016:1614-1
Summary: Security update for GraphicsMagick
Details: This update for GraphicsMagick fixes the following issues: - CVE-2016-5118: popen() shell vulnerability via special filenames (bnc#982178). - CVE-2013-4589: The ExportAlphaQuantumType function in export.c in GraphicsMagick might have allowed remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image (bsc#851064). - CVE-2015-8808: Out-of-bound read in the parsing of GIF files (bnc#965574).
References: https://www.suse.com/support/update/announcement/2016/suse-su-20161614-1/, https://bugzilla.suse.com/851064, https://bugzilla.suse.com/965574, https://bugzilla.suse.com/982178, https://www.suse.com/security/cve/CVE-2013-4589, https://www.suse.com/security/cve/CVE-2015-8808, https://www.suse.com/security/cve/CVE-2016-5118
Affected packages
Package
Name: GraphicsMagick
Purl: pkg:rpm/suse/GraphicsMagick&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
