SUSE-SU-2016:2667-1
Dashboard / Vulnerabilities / SUSE-SU-2016:2667-1
SUSE-SU-2016:2667-1
Summary: Security update for ImageMagick
Details: This update for ImageMagick fixes the following issues: These vulnerabilities could be triggered by processing specially crafted image files, which could lead to a process crash or resource consumtion, or potentially have unspecified futher impact. - CVE-2016-8684: Mismatch between real filesize and header values (bsc#1005123) - CVE-2016-8683: Check that filesize is reasonable compared to the header value (bsc#1005127) - CVE-2016-8682: Stack-buffer read overflow while reading SCT header (bsc#1005125) - CVE-2016-8677: Memory allocation failure in AcquireQuantumPixels (bsc#1005328) - CVE-2016-7996, CVE-2016-7997: WPG Reader Issues (bsc#1003629) - CVE-2016-7800: 8BIM/8BIMW unsigned underflow leads to heap overflow (bsc#1002422) - CVE-2016-7799: mogrify global buffer overflow (bsc#1002421) - CVE-2016-7540: writing to RGF format aborts (bsc#1000394) - CVE-2016-7539: Potential DOS by not releasing memory (bsc#1000715) - CVE-2016-7538: SIGABRT for corrupted pdb file (bsc#1000712) - CVE-2016-7537: Out of bound access for corrupted pdb file (bsc#1000711) - CVE-2016-7535: Out of bound access for corrupted psd file (bsc#1000709) - CVE-2016-7534: Out of bound access in generic decoder (bsc#1000708) - CVE-2016-7533: Wpg file out of bound for corrupted file (bsc#1000707) - CVE-2016-7532: fix handling of corrupted psd file (bsc#1000706) - CVE-2016-7531: Pbd file out of bound access (bsc#1000704) - CVE-2016-7530: Out of bound in quantum handling (bsc#1000703) - CVE-2016-7529: Out-of-bound in quantum handling (bsc#1000399) - CVE-2016-7528: Out-of-bound access in xcf file coder (bsc#1000434) - CVE-2016-7527: Out-of-bound access in wpg file coder: (bsc#1000436) - CVE-2016-7526: out-of-bounds write in ./MagickCore/pixel-accessor.h (bsc#1000702) - CVE-2016-7525: Heap buffer overflow in psd file coder (bsc#1000701) - CVE-2016-7524: AddressSanitizer:heap-buffer-overflow READ of size 1 in meta.c:465 (bsc#1000700) - CVE-2016-7523: AddressSanitizer:heap-buffer-overflow READ of size 1 meta.c:496 (bsc#1000699) - CVE-2016-7522: Out of bound access for malformed psd file (bsc#1000698) - CVE-2016-7521: Heap buffer overflow in psd file handling (bsc#1000697) - CVE-2016-7520: Heap overflow in hdr file handling (bsc#1000696) - CVE-2016-7519: Out-of-bounds read in coders/rle.c (bsc#1000695) - CVE-2016-7518: Out-of-bounds read in coders/sun.c (bsc#1000694) - CVE-2016-7517: Out-of-bounds read in coders/pict.c (bsc#1000693) - CVE-2016-7516: Out-of-bounds problem in rle, pict, viff and sun files (bsc#1000692) - CVE-2016-7515: Rle file handling for corrupted file (bsc#1000689) - CVE-2016-7514: Out-of-bounds read in coders/psd.c (bsc#1000688) - CVE-2016-7513: Off-by-one error leading to segfault (bsc#1000686) - CVE-2016-7101: raphicsMagick: SGI Coder Out-Of-Bounds Read Vulnerability (bsc#1001221) - CVE-2016-6823: raphicsMagick: BMP Coder Out-Of-Bounds Write Vulnerability (bsc#1001066) - CVE-2015-8959: dOS due to corrupted DDS files (bsc#1000713) - CVE-2015-8958: Potential DOS in sun file handling due to malformed files (bsc#1000691) - CVE-2015-8957: Buffer overflow in sun file handling (bsc#1000690) - CVE-2014-9907: DOS due to corrupted DDS files (bsc#1000714) - Buffer overflows in SIXEL, PDB, MAP, and TIFF coders (bsc#1002209) - Divide by zero in WriteTIFFImage (bsc#1002206)
References: https://www.suse.com/support/update/announcement/2016/suse-su-20162667-1/, https://bugzilla.suse.com/1000394, https://bugzilla.suse.com/1000399, https://bugzilla.suse.com/1000434, https://bugzilla.suse.com/1000436, https://bugzilla.suse.com/1000686, https://bugzilla.suse.com/1000688, https://bugzilla.suse.com/1000689, https://bugzilla.suse.com/1000690, https://bugzilla.suse.com/1000691, https://bugzilla.suse.com/1000692, https://bugzilla.suse.com/1000693, https://bugzilla.suse.com/1000694, https://bugzilla.suse.com/1000695, https://bugzilla.suse.com/1000696, https://bugzilla.suse.com/1000697, https://bugzilla.suse.com/1000698, https://bugzilla.suse.com/1000699, https://bugzilla.suse.com/1000700, https://bugzilla.suse.com/1000701, https://bugzilla.suse.com/1000702, https://bugzilla.suse.com/1000703, https://bugzilla.suse.com/1000704, https://bugzilla.suse.com/1000706, https://bugzilla.suse.com/1000707, https://bugzilla.suse.com/1000708, https://bugzilla.suse.com/1000709, https://bugzilla.suse.com/1000711, https://bugzilla.suse.com/1000712, https://bugzilla.suse.com/1000713, https://bugzilla.suse.com/1000714, https://bugzilla.suse.com/1000715, https://bugzilla.suse.com/1001066, https://bugzilla.suse.com/1001221, https://bugzilla.suse.com/1002206, https://bugzilla.suse.com/1002209, https://bugzilla.suse.com/1002421, https://bugzilla.suse.com/1002422, https://bugzilla.suse.com/1003629, https://bugzilla.suse.com/1005123, https://bugzilla.suse.com/1005125, https://bugzilla.suse.com/1005127, https://bugzilla.suse.com/1005328, https://www.suse.com/security/cve/CVE-2014-9907, https://www.suse.com/security/cve/CVE-2015-8957, https://www.suse.com/security/cve/CVE-2015-8958, https://www.suse.com/security/cve/CVE-2015-8959, https://www.suse.com/security/cve/CVE-2016-6823, https://www.suse.com/security/cve/CVE-2016-7101, https://www.suse.com/security/cve/CVE-2016-7513, https://www.suse.com/security/cve/CVE-2016-7514, https://www.suse.com/security/cve/CVE-2016-7515, https://www.suse.com/security/cve/CVE-2016-7516, https://www.suse.com/security/cve/CVE-2016-7517, https://www.suse.com/security/cve/CVE-2016-7518, https://www.suse.com/security/cve/CVE-2016-7519, https://www.suse.com/security/cve/CVE-2016-7520, https://www.suse.com/security/cve/CVE-2016-7521, https://www.suse.com/security/cve/CVE-2016-7522, https://www.suse.com/security/cve/CVE-2016-7523, https://www.suse.com/security/cve/CVE-2016-7524, https://www.suse.com/security/cve/CVE-2016-7525, https://www.suse.com/security/cve/CVE-2016-7526, https://www.suse.com/security/cve/CVE-2016-7527, https://www.suse.com/security/cve/CVE-2016-7528, https://www.suse.com/security/cve/CVE-2016-7529, https://www.suse.com/security/cve/CVE-2016-7530, https://www.suse.com/security/cve/CVE-2016-7531, https://www.suse.com/security/cve/CVE-2016-7532, https://www.suse.com/security/cve/CVE-2016-7533, https://www.suse.com/security/cve/CVE-2016-7534, https://www.suse.com/security/cve/CVE-2016-7535, https://www.suse.com/security/cve/CVE-2016-7537, https://www.suse.com/security/cve/CVE-2016-7538, https://www.suse.com/security/cve/CVE-2016-7539, https://www.suse.com/security/cve/CVE-2016-7540, https://www.suse.com/security/cve/CVE-2016-7799, https://www.suse.com/security/cve/CVE-2016-7800, https://www.suse.com/security/cve/CVE-2016-7996, https://www.suse.com/security/cve/CVE-2016-7997, https://www.suse.com/security/cve/CVE-2016-8677, https://www.suse.com/security/cve/CVE-2016-8682, https://www.suse.com/security/cve/CVE-2016-8683, https://www.suse.com/security/cve/CVE-2016-8684
Affected packages
Package
Name: ImageMagick
Purl: pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1
Affected ranges
Type: ECOSYSTEM
Events:
