Security update for GraphicsMagick
This update for GraphicsMagick fixes the following issues: - CVE-2016-5118: popen() shell vulnerability via special filenames (bnc#982178). - CVE-2013-4589: The ExportAlphaQuantumType function in export.c in GraphicsMagick might have allowed remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image (bsc#851064). - CVE-2015-8808: Out-of-bound read in the parsing of GIF files (bnc#965574).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for GraphicsMagick fixes the following issues: - CVE-2016-5118: popen() shell vulnerability via special filenames (bnc#982178). - CVE-2013-4589: The ExportAlphaQuantumType function in export.c in GraphicsMagick might have allowed remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image (bsc#851064). - CVE-2015-8808: Out-of-bound read in the parsing of GIF files (bnc#965574).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/851064
- https://bugzilla.suse.com/965574
- https://bugzilla.suse.com/982178
- https://www.suse.com/security/cve/CVE-2013-4589
- https://www.suse.com/security/cve/CVE-2015-8808
- https://www.suse.com/security/cve/CVE-2016-5118
- https://www.suse.com/support/update/announcement/2016/suse-su-20161614-1/