SUSE-SU-2018:2778-1
Dashboard / Vulnerabilities / SUSE-SU-2018:2778-1
SUSE-SU-2018:2778-1
Summary: Security update for ImageMagick
Details: This update for ImageMagick fixes the following issues: The following security vulnerabilities were fixed: - CVE-2018-16329: Prevent NULL pointer dereference in the GetMagickProperty function leading to DoS (bsc#1106858) - CVE-2018-16323: ReadXBMImage left data uninitialized when processing an XBM file that has a negative pixel value. If the affected code was used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data (bsc#1106855) - CVE-2018-14434: Fixed a memory leak for a colormap in WriteMPCImage (bsc#1102003) - CVE-2018-14435: Fixed a memory leak in DecodeImage in coders/pcd.c (bsc#1102007) - CVE-2018-14436: Fixed a memory leak in ReadMIFFImage in coders/miff.c (bsc#1102005) - CVE-2018-14437: Fixed a memory leak in parse8BIM in coders/meta.c (bsc#1102004) - Disable PS, PS2, PS3, XPS and PDF coders in default policy.xml (bsc#1105592)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20182778-1/, https://bugzilla.suse.com/1102003, https://bugzilla.suse.com/1102004, https://bugzilla.suse.com/1102005, https://bugzilla.suse.com/1102007, https://bugzilla.suse.com/1105592, https://bugzilla.suse.com/1106855, https://bugzilla.suse.com/1106858, https://www.suse.com/security/cve/CVE-2018-14434, https://www.suse.com/security/cve/CVE-2018-14435, https://www.suse.com/security/cve/CVE-2018-14436, https://www.suse.com/security/cve/CVE-2018-14437, https://www.suse.com/security/cve/CVE-2018-16323, https://www.suse.com/security/cve/CVE-2018-16329
Affected packages
Package
Name: ImageMagick
Purl: pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
