[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2018:0043-1 -- SLES libMagickCore1

ID: oval:org.secpod.oval:def:89043894Date: (C)2021-03-05   (M)2022-07-08
Class: PATCHFamily: unix




This update for ImageMagick fixes several issues. These security issues were fixed: - CVE-2017-14343: Fixed a memory leak vulnerability in ReadXCFImage in coders/xcf.c via a crafted xcf image file . - CVE-2017-12691: The ReadOneLayer function in coders/xcf.c allowed remote attackers to cause a denial of service via a crafted file . - CVE-2017-14042: Prevent memory allocation failure in the ReadPNMImage function in coders/pnm.c. The vulnerability caused a big memory allocation, which may have lead to remote denial of service in the MagickRealloc function in magick/memory.c . - CVE-2017-15281: ReadPSDImage in coders/psd.c allowed remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted file . - CVE-2017-13061: A length-validation vulnerability in the function ReadPSDLayersInternal in coders/psd.c allowed attackers to cause a denial of service via a crafted file . - CVE-2017-12563: A memory exhaustion vulnerability in the function ReadPSDImage in coders/psd.c allowed attackers to cause a denial of service . - CVE-2017-14174: coders/psd.c allowed for DoS in ReadPSDLayersInternal due to lack of an EOF check might have caused huge CPU consumption. When a crafted PSD file, which claims a large length field in the header but did not contain sufficient backing data, is provided, the loop over length would consume huge CPU resources, since there is no EOF check inside the loop . - CVE-2017-13062: A memory leak vulnerability in the function formatIPTC in coders/meta.c allowed attackers to cause a denial of service via a crafted file . - CVE-2017-15277: ReadGIFImage in coders/gif.c left the palette uninitialized when processing a GIF file that has neither a global nor local palette. If this functionality was used as a library loaded into a process that operates on interesting data, this data sometimes could have been leaked via the uninitialized palette .

Platform:
SUSE Linux Enterprise Server 11 SP4
Product:
libMagickCore1
Reference:
SUSE-SU-2018:0043-1
CVE-2017-12563
CVE-2017-12691
CVE-2017-13061
CVE-2017-13062
CVE-2017-14042
CVE-2017-14174
CVE-2017-14343
CVE-2017-15277
CVE-2017-15281
CVE    9
CVE-2017-12563
CVE-2017-12691
CVE-2017-13062
CVE-2017-14042
...

© SecPod Technologies