openSUSE-SU-2019:1272-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:1272-1
openSUSE-SU-2019:1272-1
Summary: Security update for GraphicsMagick
Details: This update for GraphicsMagick fixes the following issues: - CVE-2019-11005: Fixed a stack-based buffer overflow in SVGStartElement of coders/svg.c that allowed attackers to cause DOS or an unspecified impact (boo#1132058) - CVE-2019-11006: Fixed a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c that allowed attackers to cause DOS or information disclosure (boo#1132061) - CVE-2019-11010: Fixed a memory leak in ReadMPCImage of coders/mpc.c that which allowed attackers to cause DOS via a crafted image file (boo#1132055) - CVE-2019-11007: Fixed a heap-based buffer over-read in the ReadMNGImage function of coders/png.c that which allowed attackers to cause a denial of service or information disclosure (boo#1132060) - CVE-2019-11008: Fixed a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c that which allowed remote attackers to cause DOS or other unspecified impact (boo#1132054) - CVE-2019-11009: Fixed a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c that which allowed attackers to cause DOS or information disclosure (boo#1132053)
References: https://lists.opensuse.org/archives/list/[email protected]/thread/EXCD25J6SGUE4ICG6PUTWAN5C5PUNGAD/#EXCD25J6SGUE4ICG6PUTWAN5C5PUNGAD, https://bugzilla.suse.com/1132053, https://bugzilla.suse.com/1132054, https://bugzilla.suse.com/1132055, https://bugzilla.suse.com/1132058, https://bugzilla.suse.com/1132060, https://bugzilla.suse.com/1132061, https://www.suse.com/security/cve/CVE-2019-11005, https://www.suse.com/security/cve/CVE-2019-11006, https://www.suse.com/security/cve/CVE-2019-11007, https://www.suse.com/security/cve/CVE-2019-11008, https://www.suse.com/security/cve/CVE-2019-11009, https://www.suse.com/security/cve/CVE-2019-11010
Affected packages
Package
Name: GraphicsMagick
Purl: pkg:rpm/opensuse/GraphicsMagick&distro=openSUSE%20Leap%2015.0
Affected ranges
Type: ECOSYSTEM
Events:
