Security update for GraphicsMagick
This update for GraphicsMagick fixes the following issues: Security issues fixed: - CVE-2017-9405: A memory leak in the ReadICONImage function was fixed that could lead to DoS via memory exhaustion (bsc#1042911) - CVE-2017-11528: ReadDIBImage in coders/dib.c allows remote attackers to cause DoS via memory exhaustion (bsc#1050119) - CVE-2017-11533: A information leak by 1 byte due to heap-based buffer over-read in the WriteUILImage() in coders/uil.c was fixed (bsc#1050132) - CVE-2017-12663: A memory leak in WriteMAPImage in coders/map.c was fixed that could lead to a DoS via memory exhaustion (bsc#1052754) - CVE-2017-17682: A large loop vulnerability was fixed in ExtractPostscript in coders/wpg.c, which allowed attackers to cause a denial of service (CPU exhaustion) (bsc#1072898) - CVE-2017-17500: A heap-based buffer overflow (read) in the ImportRGBQuantumType was fixed. (bsc#1077737)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for GraphicsMagick fixes the following issues: Security issues fixed: - CVE-2017-9405: A memory leak in the ReadICONImage function was fixed that could lead to DoS via memory exhaustion (bsc#1042911) - CVE-2017-11528: ReadDIBImage in coders/dib.c allows remote attackers to cause DoS via memory exhaustion (bsc#1050119) - CVE-2017-11533: A information leak by 1 byte due to heap-based buffer over-read in the WriteUILImage() in coders/uil.c was fixed (bsc#1050132) - CVE-2017-12663: A memory leak in WriteMAPImage in coders/map.c was fixed that could lead to a DoS via memory exhaustion (bsc#1052754) - CVE-2017-17682: A large loop vulnerability was fixed in ExtractPostscript in coders/wpg.c, which allowed attackers to cause a denial of service (CPU exhaustion) (bsc#1072898) - CVE-2017-17500: A heap-based buffer overflow (read) in the ImportRGBQuantumType was fixed. (bsc#1077737)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1042911
- https://bugzilla.suse.com/1050119
- https://bugzilla.suse.com/1050132
- https://bugzilla.suse.com/1052754
- https://bugzilla.suse.com/1072898
- https://bugzilla.suse.com/1077737
- https://www.suse.com/security/cve/CVE-2017-11528
- https://www.suse.com/security/cve/CVE-2017-11533
- https://www.suse.com/security/cve/CVE-2017-12663
- https://www.suse.com/security/cve/CVE-2017-17500
- https://www.suse.com/security/cve/CVE-2017-17682
- https://www.suse.com/security/cve/CVE-2017-9405
- https://www.suse.com/support/update/announcement/2018/suse-su-20180672-1/