SUSE-SU-2018:0672-1
Dashboard / Vulnerabilities / SUSE-SU-2018:0672-1
SUSE-SU-2018:0672-1
Summary: Security update for GraphicsMagick
Details: This update for GraphicsMagick fixes the following issues: Security issues fixed: - CVE-2017-9405: A memory leak in the ReadICONImage function was fixed that could lead to DoS via memory exhaustion (bsc#1042911) - CVE-2017-11528: ReadDIBImage in coders/dib.c allows remote attackers to cause DoS via memory exhaustion (bsc#1050119) - CVE-2017-11533: A information leak by 1 byte due to heap-based buffer over-read in the WriteUILImage() in coders/uil.c was fixed (bsc#1050132) - CVE-2017-12663: A memory leak in WriteMAPImage in coders/map.c was fixed that could lead to a DoS via memory exhaustion (bsc#1052754) - CVE-2017-17682: A large loop vulnerability was fixed in ExtractPostscript in coders/wpg.c, which allowed attackers to cause a denial of service (CPU exhaustion) (bsc#1072898) - CVE-2017-17500: A heap-based buffer overflow (read) in the ImportRGBQuantumType was fixed. (bsc#1077737)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20180672-1/, https://bugzilla.suse.com/1042911, https://bugzilla.suse.com/1050119, https://bugzilla.suse.com/1050132, https://bugzilla.suse.com/1052754, https://bugzilla.suse.com/1072898, https://bugzilla.suse.com/1077737, https://www.suse.com/security/cve/CVE-2017-11528, https://www.suse.com/security/cve/CVE-2017-11533, https://www.suse.com/security/cve/CVE-2017-12663, https://www.suse.com/security/cve/CVE-2017-17500, https://www.suse.com/security/cve/CVE-2017-17682, https://www.suse.com/security/cve/CVE-2017-9405
Affected packages
Package
Name: GraphicsMagick
Purl: pkg:rpm/suse/GraphicsMagick&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
