SUSE-SU-2019:13923-1
Dashboard / Vulnerabilities / SUSE-SU-2019:13923-1
SUSE-SU-2019:13923-1
Summary: Security update for GraphicsMagick
Details: This update for GraphicsMagick fixes the following issues: Security issues fixed: - CVE-2018-18544: Fixed memory leak in the function WriteMSLImage() (bsc#1113064). - CVE-2017-10794: Fixed buffer overflow in RGB TIFF picture processing (bsc#1112392). - CVE-2017-14997: Fixed integer underflow in ReadPICTImage in coders/pict.c (bsc#1112399). - CVE-2018-20185: Fixed heap-based buffer over-read in the ReadBMPImage function of bmp.c (bsc#1119823) - CVE-2018-20184: Fixed heap-based buffer overflow in the WriteTGAImage function of tga.c (bsc#1119822) Regressions fixed after security update: - CVE-2017-12663: Fixed memory leak in WriteMAPImage in coders/map.c (bsc#1052754). - CVE-2017-9405: Fixed memory leak in the ReadICONImage function (bsc#1042911). - CVE-2018-6405: Fixed ReadDCMImage function in coders/dcm (bsc#1078433). Non-security issues fixed: - debug_build: build more suitable for debugging
References: https://www.suse.com/support/update/announcement/2019/suse-su-201913923-1/, https://bugzilla.suse.com/1042911, https://bugzilla.suse.com/1052754, https://bugzilla.suse.com/1078433, https://bugzilla.suse.com/1112392, https://bugzilla.suse.com/1112399, https://bugzilla.suse.com/1113064, https://bugzilla.suse.com/1119822, https://bugzilla.suse.com/1119823, https://www.suse.com/security/cve/CVE-2017-10794, https://www.suse.com/security/cve/CVE-2017-12663, https://www.suse.com/security/cve/CVE-2017-14997, https://www.suse.com/security/cve/CVE-2017-9405, https://www.suse.com/security/cve/CVE-2018-18544, https://www.suse.com/security/cve/CVE-2018-20184, https://www.suse.com/security/cve/CVE-2018-20185, https://www.suse.com/security/cve/CVE-2018-6405
Affected packages
Package
Name: GraphicsMagick
Purl: pkg:rpm/suse/GraphicsMagick&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
