Security update for ImageMagick
This update for ImageMagick fixes the following issues: - CVE-2017-14997: ImageMagick allowed remote attackers to cause a denial of service (excessive memory allocation) because of an integer underflow in ReadPICTImage in coders/pict.c. (bsc#1112399) - CVE-2018-16644: A regression in the security fix for the pict coder was fixed (bsc#1107609) - CVE-2017-11532: When ImageMagick processed a crafted file in convert, it could lead to a Memory Leak in the WriteMPCImage() function in coders/mpc.c. (bsc#1050129) - CVE-2017-11639: A regression in the security fix in the cip coder was fixed (bsc#1050635)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for ImageMagick fixes the following issues: - CVE-2017-14997: ImageMagick allowed remote attackers to cause a denial of service (excessive memory allocation) because of an integer underflow in ReadPICTImage in coders/pict.c. (bsc#1112399) - CVE-2018-16644: A regression in the security fix for the pict coder was fixed (bsc#1107609) - CVE-2017-11532: When ImageMagick processed a crafted file in convert, it could lead to a Memory Leak in the WriteMPCImage() function in coders/mpc.c. (bsc#1050129) - CVE-2017-11639: A regression in the security fix in the cip coder was fixed (bsc#1050635)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1050129
- https://bugzilla.suse.com/1050635
- https://bugzilla.suse.com/1107609
- https://bugzilla.suse.com/1112399
- https://www.suse.com/security/cve/CVE-2017-11532
- https://www.suse.com/security/cve/CVE-2017-11639
- https://www.suse.com/security/cve/CVE-2017-14997
- https://www.suse.com/security/cve/CVE-2018-16644
- https://www.suse.com/support/update/announcement/2018/suse-su-20183808-1/