SUSE-SU-2018:0132-1 -- SLES libMagickCore1ID: oval:org.secpod.oval:def:89043621 | Date: (C)2021-03-05 (M)2024-04-04 |
Class: PATCH | Family: unix |
This update for ImageMagick fixes several issues. These security issues were fixed: - CVE-2017-12672: Fixed a memory leak vulnerability in the function ReadMATImage in coders/mat.c, which allowed attackers to cause a denial of service . - CVE-2017-13060: Fixed a memory leak vulnerability in the function ReadMATImage in coders/mat.c, which allowed attackers to cause a denial of service via a crafted file . - CVE-2017-11724: Fixed a memory leak vulnerability in the function ReadMATImage in coders/mat.c involving the quantum_info and clone_info data structures . - CVE-2017-12670: Added validation in coders/mat.c to prevent an assertion failure in the function DestroyImage in MagickCore/image.c, which allowed attackers to cause a denial of service . - CVE-2017-12667: Fixed a memory leak vulnerability in the function ReadMATImage in coders/mat.c . - CVE-2017-13146: Fixed a memory leak vulnerability in the function ReadMATImage in coders/mat.c . - CVE-2017-10800: Processing MATLAB images in coders/mat.c could have lead to a denial of service in ReadMATImage if the size specified for a MAT Object was larger than the actual amount of data - CVE-2017-13648: Fixed a memory leak vulnerability in the function ReadMATImage in coders/mat.c . - CVE-2017-11141: Fixed a memory leak vulnerability in the function ReadMATImage in coders\mat.c that could have caused memory exhaustion via a crafted MAT file, related to incorrect ordering of a SetImageExtent call . - CVE-2017-11529: The ReadMATImage function in coders/mat.c allowed remote attackers to cause a denial of service via a crafted file . - CVE-2017-12564: Fixed a memory leak vulnerability in the function ReadMATImage in coders/mat.c, which allowed attackers to cause a denial of service . - CVE-2017-12434: Added a missing NULL check in the function ReadMATImage in coders/mat.c, which allowed attackers to cause a denial of service in DestroyImageInfo in image.c . - CVE-2017-12675: Added a missing check for multidimensional data coders/mat.c, that could have lead to a memory leak in the function ReadImage in MagickCore/constitute.c, which allowed attackers to cause a denial of service . - CVE-2017-14326: Fixed a memory leak vulnerability in the function ReadMATImage in coders/mat.c, which allowed attackers to cause a denial of service via a crafted file . - CVE-2017-11644: Processesing a crafted file in convert could have lead to a memory leak in the ReadMATImage function in coders/mat.c . - CVE-2017-13658: Added a missing NULL check in the ReadMATImage function in coders/mat.c, which could have lead to a denial of service in the DestroyImageInfo function in MagickCore/image.c . - CVE-2017-14533: Fixed a memory leak vulnerability in the function ReadMATImage in coders/mat.c . - CVE-2017-17881: Fixed a memory leak vulnerability in the function ReadMATImage in coders/mat.c, which allowed attackers to cause a denial of service via a crafted MAT image file . - CVE-2017-1000476: Prevent CPU exhaustion in the function ReadDDSInfo in coders/dds.c, which allowed attackers to cause a denial of service . - CVE-2017-9409: Fixed a memory leak vulnerability in the function ReadMPCImage in mpc.c, which allowed attackers to cause a denial of service via a crafted file . - CVE-2017-11449: coders/mpc did not enable seekable streams and thus could not validate blob sizes, which allowed remote attackers to cause a denial of service or possibly have unspecified other impact via an image received from stdin - CVE-2017-12430: A memory exhaustion in the function ReadMPCImage in coders/mpc.c allowed attackers to cause DoS - CVE-2017-12642: Prevent a memory leak vulnerability in ReadMPCImage in coders\mpc.c via crafted file allowing for DoS - CVE-2017-14249: A mishandled EOF check in ReadMPCImage in coders/mpc.c that lead to a division by zero in GetPixelCacheTileSize in MagickCore/cache.c allowed remote attackers to cause a denial of service via a crafted file - CVE-2017-1000445: Added a NUL pointer check in the MagickCore component that might have lead to denial of service . - CVE-2017-11751: Fixed a memory leak vulnerability in the function WritePICONImage in coders/xpm.c that allowed remote attackers to cause a denial of service via a crafted file . - CVE-2017-17680: Fixed a memory leak vulnerability in the function ReadXPMImage in coders/xpm.c, which allowed attackers to cause a denial of service via a crafted xpm image file . - CVE-2017-17882: Fixed a memory leak vulnerability in the function ReadXPMImage in coders/xpm.c, which allowed attackers to cause a denial of service via a crafted XPM image file . - CVE-2018-5246: Fixed memory leak vulnerability in ReadPATTERNImage in coders/pattern.c . - CVE-2017-18022: Fixed memory leak vulnerability in MontageImageCommand in MagickWand/montage.c - CVE-2018-5247: Fixed memory leak vulnerability in ReadRLAImage in coders/rla.c
Platform: |
SUSE Linux Enterprise Server 11 SP4 |