SUSE-SU-2018:3808-1
Dashboard / Vulnerabilities / SUSE-SU-2018:3808-1
SUSE-SU-2018:3808-1
Summary: Security update for ImageMagick
Details: This update for ImageMagick fixes the following issues: - CVE-2017-14997: ImageMagick allowed remote attackers to cause a denial of service (excessive memory allocation) because of an integer underflow in ReadPICTImage in coders/pict.c. (bsc#1112399) - CVE-2018-16644: A regression in the security fix for the pict coder was fixed (bsc#1107609) - CVE-2017-11532: When ImageMagick processed a crafted file in convert, it could lead to a Memory Leak in the WriteMPCImage() function in coders/mpc.c. (bsc#1050129) - CVE-2017-11639: A regression in the security fix in the cip coder was fixed (bsc#1050635)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20183808-1/, https://bugzilla.suse.com/1050129, https://bugzilla.suse.com/1050635, https://bugzilla.suse.com/1107609, https://bugzilla.suse.com/1112399, https://www.suse.com/security/cve/CVE-2017-11532, https://www.suse.com/security/cve/CVE-2017-11639, https://www.suse.com/security/cve/CVE-2017-14997, https://www.suse.com/security/cve/CVE-2018-16644
Affected packages
Package
Name: ImageMagick
Purl: pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
