SUSE-SU-2021:0153-1

    Dashboard / Vulnerabilities / SUSE-SU-2021:0153-1

    SUSE-SU-2021:0153-1

    Published: 15 Jan 2021Last Modified: 4 Feb 2026

    Summary: Security update for ImageMagick

    Details: This update for ImageMagick fixes the following issues: - CVE-2020-25664: Fixed a heap-based buffer overflow in PopShortPixel (bsc#1179202). - CVE-2020-25665: Fixed a heap-based buffer overflow in WritePALMImage (bsc#1179208). - CVE-2020-25666: Fixed an outside the range of representable values of type 'int' and signed integer overflow (bsc#1179212). - CVE-2020-25674: Fixed a heap-based buffer overflow in WriteOnePNGImage (bsc#1179223). - CVE-2020-25675: Fixed an outside the range of representable values of type 'long' and integer overflow (bsc#1179240). - CVE-2020-25676: Fixed an outside the range of representable values of type 'long' and integer overflow at MagickCore/pixel.c (bsc#1179244). - CVE-2020-27750: Fixed a division by zero in MagickCore/colorspace-private.h (bsc#1179260). - CVE-2020-27751: Fixed an integer overflow in MagickCore/quantum-export.c (bsc#1179269). - CVE-2020-27752: Fixed a heap-based buffer overflow in PopShortPixel in MagickCore/quantum-private.h (bsc#1179346). - CVE-2020-27752: Fixed a heap-based buffer overflow in PopShortPixel in MagickCore/quantum-private.h (bsc#1179346). - CVE-2020-27753: Fixed memory leaks in AcquireMagickMemory function (bsc#1179397). - CVE-2020-27755: Fixed memory leaks in ResizeMagickMemory function in ImageMagick/MagickCore/memory.c (bsc#1179345). - CVE-2020-27756: Fixed a division by zero at MagickCore/geometry.c (bsc#1179221). - CVE-2020-27757: Fixed an outside the range of representable values of type 'unsigned long long' at MagickCore/quantum-private.h (bsc#1179268). - CVE-2020-27758: Fixed an outside the range of representable values of type 'unsigned long long' (bsc#1179276). - CVE-2020-27759: Fixed an outside the range of representable values of type 'int' at MagickCore/quantize.c (bsc#1179313). - CVE-2020-27760: Fixed a division by zero at MagickCore/enhance.c (bsc#1179281). - CVE-2020-27761: Fixed an outside the range of representable values of type 'unsigned long' at coders/palm.c (bsc#1179315). - CVE-2020-27762: Fixed an outside the range of representable values of type 'unsigned char' (bsc#1179278). - CVE-2020-27763: Fixed a division by zero at MagickCore/resize.c (bsc#1179312). - CVE-2020-27764: Fixed an outside the range of representable values of type 'unsigned long' at MagickCore/statistic.c (bsc#1179317). - CVE-2020-27765: Fixed a division by zero at MagickCore/segment.c (bsc#1179311). - CVE-2020-27766: Fixed an outside the range of representable values of type 'unsigned long' at MagickCore/statistic.c (bsc#1179361). - CVE-2020-27767: Fixed an outside the range of representable values of type 'float' at MagickCore/quantum.h (bsc#1179322). - CVE-2020-27768: Fixed an outside the range of representable values of type 'unsigned int' at MagickCore/quantum-private.h (bsc#1179339). - CVE-2020-27770: Fixed an unsigned offset overflowed at MagickCore/string.c (bsc#1179343). - CVE-2020-27771: Fixed an outside the range of representable values of type 'unsigned char' at coders/pdf.c (bsc#1179327). - CVE-2020-27772: Fixed an outside the range of representable values of type 'unsigned int' at coders/bmp.c (bsc#1179347). - CVE-2020-27773: Fixed a division by zero at MagickCore/gem-private.h (bsc#1179285). - CVE-2020-27774: Fixed an integer overflow at MagickCore/statistic.c (bsc#1179333). - CVE-2020-27775: Fixed an outside the range of representable values of type 'unsigned char' at MagickCore/quantum.h (bsc#1179338). - CVE-2020-27776: Fixed an outside the range of representable values of type 'unsigned long' at MagickCore/statistic.c (bsc#1179362). - CVE-2020-29599: Fixed a shell command injection in -authenticate (bsc#1179753).

    References: https://www.suse.com/support/update/announcement/2021/suse-su-20210153-1/, https://bugzilla.suse.com/1179202, https://bugzilla.suse.com/1179208, https://bugzilla.suse.com/1179212, https://bugzilla.suse.com/1179221, https://bugzilla.suse.com/1179223, https://bugzilla.suse.com/1179240, https://bugzilla.suse.com/1179244, https://bugzilla.suse.com/1179260, https://bugzilla.suse.com/1179268, https://bugzilla.suse.com/1179269, https://bugzilla.suse.com/1179276, https://bugzilla.suse.com/1179278, https://bugzilla.suse.com/1179281, https://bugzilla.suse.com/1179285, https://bugzilla.suse.com/1179311, https://bugzilla.suse.com/1179312, https://bugzilla.suse.com/1179313, https://bugzilla.suse.com/1179315, https://bugzilla.suse.com/1179317, https://bugzilla.suse.com/1179321, https://bugzilla.suse.com/1179322, https://bugzilla.suse.com/1179327, https://bugzilla.suse.com/1179333, https://bugzilla.suse.com/1179336, https://bugzilla.suse.com/1179338, https://bugzilla.suse.com/1179339, https://bugzilla.suse.com/1179343, https://bugzilla.suse.com/1179345, https://bugzilla.suse.com/1179346, https://bugzilla.suse.com/1179347, https://bugzilla.suse.com/1179361, https://bugzilla.suse.com/1179362, https://bugzilla.suse.com/1179397, https://bugzilla.suse.com/1179753, https://www.suse.com/security/cve/CVE-2020-25664, https://www.suse.com/security/cve/CVE-2020-25665, https://www.suse.com/security/cve/CVE-2020-25666, https://www.suse.com/security/cve/CVE-2020-25674, https://www.suse.com/security/cve/CVE-2020-25675, https://www.suse.com/security/cve/CVE-2020-25676, https://www.suse.com/security/cve/CVE-2020-27750, https://www.suse.com/security/cve/CVE-2020-27751, https://www.suse.com/security/cve/CVE-2020-27752, https://www.suse.com/security/cve/CVE-2020-27753, https://www.suse.com/security/cve/CVE-2020-27754, https://www.suse.com/security/cve/CVE-2020-27755, https://www.suse.com/security/cve/CVE-2020-27756, https://www.suse.com/security/cve/CVE-2020-27757, https://www.suse.com/security/cve/CVE-2020-27758, https://www.suse.com/security/cve/CVE-2020-27759, https://www.suse.com/security/cve/CVE-2020-27760, https://www.suse.com/security/cve/CVE-2020-27761, https://www.suse.com/security/cve/CVE-2020-27762, https://www.suse.com/security/cve/CVE-2020-27763, https://www.suse.com/security/cve/CVE-2020-27764, https://www.suse.com/security/cve/CVE-2020-27765, https://www.suse.com/security/cve/CVE-2020-27766, https://www.suse.com/security/cve/CVE-2020-27767, https://www.suse.com/security/cve/CVE-2020-27768, https://www.suse.com/security/cve/CVE-2020-27769, https://www.suse.com/security/cve/CVE-2020-27770, https://www.suse.com/security/cve/CVE-2020-27771, https://www.suse.com/security/cve/CVE-2020-27772, https://www.suse.com/security/cve/CVE-2020-27773, https://www.suse.com/security/cve/CVE-2020-27774, https://www.suse.com/security/cve/CVE-2020-27775, https://www.suse.com/security/cve/CVE-2020-27776, https://www.suse.com/security/cve/CVE-2020-29599

    Affected packages

    Package

    Name: ImageMagick

    Purl: pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP2

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -7.0.7.34-10.9.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2021:0153-1 | CVE-DB