openSUSE-SU-2021:0606-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:0606-1
openSUSE-SU-2021:0606-1
Summary: Security update for ImageMagick
Details: This update for ImageMagick fixes the following issues: - CVE-2021-20309: Division by zero in WaveImage() of MagickCore/visual-effects. (bsc#1184624) - CVE-2021-20311: Division by zero in sRGBTransformImage() in MagickCore/colorspace.c (bsc#1184626) - CVE-2021-20312: Integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c (bsc#1184627) - CVE-2021-20313: Cipher leak when the calculating signatures in TransformSignatureof MagickCore/signature.c (bsc#1184628) This update was imported from the SUSE:SLE-15-SP2:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/QPPJFFJWUIW3K6NB472QVFG522DWQZET/, https://bugzilla.suse.com/1184624, https://bugzilla.suse.com/1184626, https://bugzilla.suse.com/1184627, https://bugzilla.suse.com/1184628, https://www.suse.com/security/cve/CVE-2021-20309, https://www.suse.com/security/cve/CVE-2021-20311, https://www.suse.com/security/cve/CVE-2021-20312, https://www.suse.com/security/cve/CVE-2021-20313
Affected packages
Package
Name: ImageMagick
Purl: pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Leap%2015.2
Affected ranges
Type: ECOSYSTEM
Events:
