[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2018:0130-1 -- SLES ImageMagick, libMagickCore-6_Q16-1, libMagickWand-6_Q16-1

ID: oval:org.secpod.oval:def:89043692Date: (C)2021-03-05   (M)2022-10-10
Class: PATCHFamily: unix




This update for ImageMagick fixes several issues. These security issues were fixed: - CVE-2018-5246: Fixed memory leak vulnerability in ReadPATTERNImage in coders/pattern.c - CVE-2017-18022: Fixed memory leak vulnerability in MontageImageCommand in MagickWand/montage.c - CVE-2018-5247: Fixed memory leak vulnerability in ReadRLAImage in coders/rla.c - CVE-2017-12672: Fixed a memory leak vulnerability in the function ReadMATImage in coders/mat.c, which allowed attackers to cause a denial of service - CVE-2017-13060: Fixed a memory leak vulnerability in the function ReadMATImage in coders/mat.c, which allowed attackers to cause a denial of service via a crafted file - CVE-2017-11724: Fixed a memory leak vulnerability in the function ReadMATImage in coders/mat.c involving the quantum_info and clone_info data structures - CVE-2017-12670: Added validation in coders/mat.c to prevent an assertion failure in the function DestroyImage in MagickCore/image.c, which allowed attackers to cause a denial of service - CVE-2017-12667: Fixed a memory leak vulnerability in the function ReadMATImage in coders/mat.c - CVE-2017-13146: Fixed a memory leak vulnerability in the function ReadMATImage in coders/mat.c - CVE-2017-10800: Processing MATLAB images in coders/mat.c could have lead to a denial of service in ReadMATImage if the size specified for a MAT Object was larger than the actual amount of data - CVE-2017-13648: Fixed a memory leak vulnerability in the function ReadMATImage in coders/mat.c - CVE-2017-11141: Fixed a memory leak vulnerability in the function ReadMATImage in coders\mat.c that could have caused memory exhaustion via a crafted MAT file, related to incorrect ordering of a SetImageExtent call - CVE-2017-11529: The ReadMATImage function in coders/mat.c allowed remote attackers to cause a denial of service via a crafted file - CVE-2017-12564: Fixed a memory leak vulnerability in the function ReadMATImage in coders/mat.c, which allowed attackers to cause a denial of service - CVE-2017-12434: Added a missing NULL check in the function ReadMATImage in coders/mat.c, which allowed attackers to cause a denial of service in DestroyImageInfo in image.c - CVE-2017-12675: Added a missing check for multidimensional data coders/mat.c, that could have lead to a memory leak in the function ReadImage in MagickCore/constitute.c, which allowed attackers to cause a denial of service - CVE-2017-14326: Fixed a memory leak vulnerability in the function ReadMATImage in coders/mat.c, which allowed attackers to cause a denial of service via a crafted file - CVE-2017-11644: Processesing a crafted file in convert could have lead to a memory leak in the ReadMATImage function in coders/mat.c - CVE-2017-13658: Added a missing NULL check in the ReadMATImage function in coders/mat.c, which could have lead to a denial of service in the DestroyImageInfo function in MagickCore/image.c - CVE-2017-14533: Fixed a memory leak vulnerability in the function ReadMATImage in coders/mat.c - CVE-2017-17881: Fixed a memory leak vulnerability in the function ReadMATImage in coders/mat.c, which allowed attackers to cause a denial of service via a crafted MAT image file

Platform:
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP2
Product:
ImageMagick
libMagickCore-6_Q16-1
libMagickWand-6_Q16-1
Reference:
SUSE-SU-2018:0130-1
CVE-2017-10800
CVE-2017-11141
CVE-2017-11529
CVE-2017-11644
CVE-2017-11724
CVE-2017-12434
CVE-2017-12564
CVE-2017-12667
CVE-2017-12670
CVE-2017-12672
CVE-2017-12675
CVE-2017-13060
CVE-2017-13146
CVE-2017-13648
CVE-2017-13658
CVE-2017-14326
CVE-2017-14533
CVE-2017-17881
CVE-2017-18022
CVE-2018-5246
CVE-2018-5247
CVE    21
CVE-2018-5247
CVE-2017-18022
CVE-2018-5246
CVE-2017-17881
...

© SecPod Technologies