ALT-PU-2016-1708-1
Package ImageMagick updated to version 6.9.4.10-alt1 for branch sisyphus in task 166648.
Closed vulnerabilities
Modified: 2021-03-23
BDU:2017-00704
Уязвимость консольного графического редактора ImageMagick и операционной системы OpenSUSE Leap, позволяющая нарушителю загружать произвольные модули
Modified: 2025-04-20
CVE-2016-10048
Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allows remote attackers to load arbitrary modules via unspecified vectors.
- http://lists.opensuse.org/opensuse-updates/2017-02/msg00028.html
- http://lists.opensuse.org/opensuse-updates/2017-02/msg00031.html
- http://www.openwall.com/lists/oss-security/2016/12/26/9
- http://www.securityfocus.com/bid/95186
- https://bugzilla.redhat.com/show_bug.cgi?id=1410451
- https://github.com/ImageMagick/ImageMagick/commit/fc6080f1321fd21e86ef916195cc110b05d9effb
- http://lists.opensuse.org/opensuse-updates/2017-02/msg00028.html
- http://lists.opensuse.org/opensuse-updates/2017-02/msg00031.html
- http://www.openwall.com/lists/oss-security/2016/12/26/9
- http://www.securityfocus.com/bid/95186
- https://bugzilla.redhat.com/show_bug.cgi?id=1410451
- https://github.com/ImageMagick/ImageMagick/commit/fc6080f1321fd21e86ef916195cc110b05d9effb
Modified: 2025-04-20
CVE-2016-10061
The ReadGROUP4Image function in coders/tiff.c in ImageMagick before 7.0.1-10 does not check the return value of the fputc function, which allows remote attackers to cause a denial of service (crash) via a crafted image file.
- http://www.openwall.com/lists/oss-security/2016/12/26/9
- http://www.securityfocus.com/bid/95207
- https://bugzilla.redhat.com/show_bug.cgi?id=1410471
- https://github.com/ImageMagick/ImageMagick/commit/4e914bbe371433f0590cefdf3bd5f3a5710069f9
- https://github.com/ImageMagick/ImageMagick/issues/196
- http://www.openwall.com/lists/oss-security/2016/12/26/9
- http://www.securityfocus.com/bid/95207
- https://bugzilla.redhat.com/show_bug.cgi?id=1410471
- https://github.com/ImageMagick/ImageMagick/commit/4e914bbe371433f0590cefdf3bd5f3a5710069f9
- https://github.com/ImageMagick/ImageMagick/issues/196
Modified: 2025-04-12
CVE-2016-5842
MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variable, which triggers an out-of-bounds read.
- http://www.openwall.com/lists/oss-security/2016/06/23/1
- http://www.openwall.com/lists/oss-security/2016/06/25/3
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.securityfocus.com/bid/91394
- https://github.com/ImageMagick/ImageMagick/commit/d8ab7f046587f2e9f734b687ba7e6e10147c294b
- https://github.com/ImageMagick/ImageMagick/commits/7.0.2-1
- https://security.gentoo.org/glsa/201611-21
- http://www.openwall.com/lists/oss-security/2016/06/23/1
- http://www.openwall.com/lists/oss-security/2016/06/25/3
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.securityfocus.com/bid/91394
- https://github.com/ImageMagick/ImageMagick/commit/d8ab7f046587f2e9f734b687ba7e6e10147c294b
- https://github.com/ImageMagick/ImageMagick/commits/7.0.2-1
- https://security.gentoo.org/glsa/201611-21
Modified: 2025-04-20
CVE-2016-7540
coders/rgf.c in ImageMagick before 6.9.4-10 allows remote attackers to cause a denial of service (assertion failure) by converting an image to rgf format.
- http://www.openwall.com/lists/oss-security/2016/09/22/2
- http://www.securityfocus.com/bid/93228
- https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1594060
- https://bugzilla.redhat.com/show_bug.cgi?id=1378777
- https://github.com/ImageMagick/ImageMagick/commit/a0108a892f9ea3c2bb1e7a49b7d71376c2ecbff7
- https://github.com/ImageMagick/ImageMagick/pull/223
- http://www.openwall.com/lists/oss-security/2016/09/22/2
- http://www.securityfocus.com/bid/93228
- https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1594060
- https://bugzilla.redhat.com/show_bug.cgi?id=1378777
- https://github.com/ImageMagick/ImageMagick/commit/a0108a892f9ea3c2bb1e7a49b7d71376c2ecbff7
- https://github.com/ImageMagick/ImageMagick/pull/223