ALT-BU-2016-2868-1
Branch sisyphus update bulletin.
Package ImageMagick updated to version 6.9.4.10-alt1 for branch sisyphus in task 166648.
Closed vulnerabilities
BDU:2017-00704
Уязвимость консольного графического редактора ImageMagick и операционной системы OpenSUSE Leap, позволяющая нарушителю загружать произвольные модули
Modified: 2024-11-21
CVE-2016-10048
Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allows remote attackers to load arbitrary modules via unspecified vectors.
- openSUSE-SU-2017:0391
- openSUSE-SU-2017:0391
- openSUSE-SU-2017:0399
- openSUSE-SU-2017:0399
- [oss-security] 20161226 Re: CVE requests for various ImageMagick issues
- [oss-security] 20161226 Re: CVE requests for various ImageMagick issues
- 95186
- 95186
- https://bugzilla.redhat.com/show_bug.cgi?id=1410451
- https://bugzilla.redhat.com/show_bug.cgi?id=1410451
- https://github.com/ImageMagick/ImageMagick/commit/fc6080f1321fd21e86ef916195cc110b05d9effb
- https://github.com/ImageMagick/ImageMagick/commit/fc6080f1321fd21e86ef916195cc110b05d9effb
Modified: 2024-11-21
CVE-2016-10061
The ReadGROUP4Image function in coders/tiff.c in ImageMagick before 7.0.1-10 does not check the return value of the fputc function, which allows remote attackers to cause a denial of service (crash) via a crafted image file.
- [oss-security] 20161226 Re: CVE requests for various ImageMagick issues
- [oss-security] 20161226 Re: CVE requests for various ImageMagick issues
- 95207
- 95207
- https://bugzilla.redhat.com/show_bug.cgi?id=1410471
- https://bugzilla.redhat.com/show_bug.cgi?id=1410471
- https://github.com/ImageMagick/ImageMagick/commit/4e914bbe371433f0590cefdf3bd5f3a5710069f9
- https://github.com/ImageMagick/ImageMagick/commit/4e914bbe371433f0590cefdf3bd5f3a5710069f9
- https://github.com/ImageMagick/ImageMagick/issues/196
- https://github.com/ImageMagick/ImageMagick/issues/196
Modified: 2024-11-21
CVE-2016-5842
MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variable, which triggers an out-of-bounds read.
- [oss-security] 20160623 Fwd: out-of-bounds read in MagickCore/property.c:1396 could lead to memory leak/ Integer overflow read to RCE
- [oss-security] 20160623 Fwd: out-of-bounds read in MagickCore/property.c:1396 could lead to memory leak/ Integer overflow read to RCE
- [oss-security] 20160625 Re: Fwd: out-of-bounds read in MagickCore/property.c:1396 could lead to memory leak/ Integer overflow read to RCE
- [oss-security] 20160625 Re: Fwd: out-of-bounds read in MagickCore/property.c:1396 could lead to memory leak/ Integer overflow read to RCE
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- 91394
- 91394
- https://github.com/ImageMagick/ImageMagick/commit/d8ab7f046587f2e9f734b687ba7e6e10147c294b
- https://github.com/ImageMagick/ImageMagick/commit/d8ab7f046587f2e9f734b687ba7e6e10147c294b
- https://github.com/ImageMagick/ImageMagick/commits/7.0.2-1
- https://github.com/ImageMagick/ImageMagick/commits/7.0.2-1
- GLSA-201611-21
- GLSA-201611-21
Modified: 2024-11-21
CVE-2016-7540
coders/rgf.c in ImageMagick before 6.9.4-10 allows remote attackers to cause a denial of service (assertion failure) by converting an image to rgf format.
- [oss-security] 20160922 Re: CVE Requests: Various ImageMagick issues (as reported in the Debian BTS)
- [oss-security] 20160922 Re: CVE Requests: Various ImageMagick issues (as reported in the Debian BTS)
- 93228
- 93228
- https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1594060
- https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1594060
- https://bugzilla.redhat.com/show_bug.cgi?id=1378777
- https://bugzilla.redhat.com/show_bug.cgi?id=1378777
- https://github.com/ImageMagick/ImageMagick/commit/a0108a892f9ea3c2bb1e7a49b7d71376c2ecbff7
- https://github.com/ImageMagick/ImageMagick/commit/a0108a892f9ea3c2bb1e7a49b7d71376c2ecbff7
- https://github.com/ImageMagick/ImageMagick/pull/223
- https://github.com/ImageMagick/ImageMagick/pull/223
Closed bugs
getfattr Segmentation fault on x86_64