Sign Up
Log In
Log In
or
Sign Up
Places
All Projects
Status Monitor
Collapse sidebar
SUSE:SLE-12-SP1:GA
patchinfo.6403
_patchinfo
Overview
Repositories
Revisions
Requests
Users
Attributes
Meta
File _patchinfo of Package patchinfo.6403
<patchinfo incident="6403"> <issue id="1049373" tracker="bnc">VUL-1: CVE-2017-11449: ImageMagick: coders/mpc.c in ImageMagick before 7.0.6-1 remote denial of service</issue> <issue id="1052252" tracker="bnc">VUL-1: CVE-2017-12430: GraphicsMagick, ImageMagick: Memory exhaustion in ReadMPCImage in coders/mpc.c, which allows attackers to cause DoS</issue> <issue id="1072902" tracker="bnc">VUL-2: CVE-2017-17680: ImageMagick: In ImageMagick 7.0.7-12 Q16, a memory leak vulnerability was found in thefunction ReadXPMImage in coders/xpm.c, which allows attackers to cause a denialof service via a crafted xpm image</issue> <issue id="1074425" tracker="bnc">VUL-0: CVE-2017-1000445: ImageMagick: Null Pointer Dereference at SketchImage of MagickCore/fx.c</issue> <issue id="1051412" tracker="bnc">VUL-1: CVE-2017-11751: GraphicsMagick, ImageMagick: WritePICONImage in coders/xpm.c allows to cause DoS</issue> <issue id="1074610" tracker="bnc">VUL-0: CVE-2017-1000476: ImageMagick: CPU exhaustion vulnerability in function ReadDDSInfo in coders/dds.c</issue> <issue id="1058082" tracker="bnc">VUL-2: CVE-2017-14249: ImageMagick: Problems with EOF check in ReadMPCImage leads to division by zero</issue> <issue id="1074122" tracker="bnc">VUL-0: CVE-2017-17882: ImageMagick: A Memory leak in the function ReadXPMImage could lead to a denial of service</issue> <issue id="1042948" tracker="bnc">VUL-1: GraphicsMagick,ImageMagick: CVE-2017-9409 ImageMagick: Memory leak in the ReadMPCImage function</issue> <issue id="1052771" tracker="bnc">VUL-2: CVE-2017-12642: GraphicsMagick, ImageMagick: Memory leak in ReadMPCImage in coders\mpc.c</issue> <issue id="2017-9409" tracker="cve" /> <issue id="2017-17882" tracker="cve" /> <issue id="2017-12430" tracker="cve" /> <issue id="2017-14249" tracker="cve" /> <issue id="2017-1000476" tracker="cve" /> <issue id="2017-11751" tracker="cve" /> <issue id="2017-1000445" tracker="cve" /> <issue id="2017-17680" tracker="cve" /> <issue id="2017-12642" tracker="cve" /> <issue id="2017-11449" tracker="cve" /> <category>security</category> <rating>moderate</rating> <packager>pgajdos</packager> <description>This update for ImageMagick fixes several issues. These security issues were fixed: - CVE-2017-1000476: A CPU exhaustion vulnerability was found in the function ReadDDSInfo in coders/dds.c, which allowed attackers to cause a denial of service (bsc#1074610). - CVE-2017-9409: The ReadMPCImage function in mpc.c allowed attackers to cause a denial of service (memory leak) via a crafted file (bsc#1042948). - CVE-2017-1000445: A NULL pointer dereference in the MagickCore component might have lead to denial of service (bsc#1074425). - CVE-2017-17680: Prevent a memory leak in the function ReadXPMImage in coders/xpm.c, which allowed attackers to cause a denial of service via a crafted XPM image file (a different vulnerability than CVE-2017-17882) (bsc#1072902). - CVE-2017-17882: Prevent a memory leak in the function ReadXPMImage in coders/xpm.c, which allowed attackers to cause a denial of service via a crafted XPM image file (a different vulnerability than CVE-2017-17680) (bsc#1074122). - CVE-2017-11449: coders/mpc did not enable seekable streams and thus could not validate blob sizes, which allowed remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an image received from stdin (bsc#1049373). - CVE-2017-12430: A memory exhaustion in the function ReadMPCImage in coders/mpc.c allowed attackers to cause DoS (bsc#1052252). - CVE-2017-12642: Prevent a memory leak vulnerability in ReadMPCImage in coders\mpc.c via crafted file allowing for DoS (bsc#1052771). - CVE-2017-14249: A mishandled EOF check in ReadMPCImage in coders/mpc.c that lead to a division by zero in GetPixelCacheTileSize in MagickCore/cache.c allowed remote attackers to cause a denial of service via a crafted file (bsc#1058082). - Prevent memory leak via crafted file in pwp.c allowing for DoS (bsc#1051412) </description> <summary>Security update for ImageMagick</summary> </patchinfo>
Locations
Projects
Search
Status Monitor
Help
OpenBuildService.org
Documentation
API Documentation
Code of Conduct
Contact
Support
@OBShq
Terms
openSUSE Build Service is sponsored by
The Open Build Service is an
openSUSE project
.
Sign Up
Log In
Places
Places
All Projects
Status Monitor