[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2019:1019-1 -- SLES ImageMagick, libMagick++-7_Q16HDRI4, libMagick++-devel, libMagickCore-7_Q16HDRI6, libMagickWand-7_Q16HDRI6

ID: oval:org.secpod.oval:def:89050701Date: (C)2023-10-16   (M)2023-10-15
Class: PATCHFamily: unix




This update for ImageMagick fixes the following issues: Security issues fixed: - CVE-2019-9956: Fixed a stack-based buffer overflow in PopHexPixel . - CVE-2019-10650: Fixed a heap-based buffer over-read in WriteTIFFImage . - CVE-2019-11007: Fixed a heap-based buffer overflow in ReadMNGImage . - CVE-2019-11008: Fixed a heap-based buffer overflow in WriteXWDImage . - Added extra -config- packages with Postscript/EPS/PDF readers still enabled. Removing the PS decoders is used to harden ImageMagick against security issues within ghostscript. Enabling them might impact security. These are two packages that can be selected: - ImageMagick-config-7-SUSE: This has the PS decoders disabled. - ImageMagick-config-7-upstream: This has the PS decoders enabled. Depending on your local needs install either one of them. The default is the -SUSE configuration.

Platform:
SUSE Linux Enterprise Desktop 15
Product:
ImageMagick
libMagick++-7_Q16HDRI4
libMagick++-devel
libMagickCore-7_Q16HDRI6
libMagickWand-7_Q16HDRI6
Reference:
SUSE-SU-2019:1019-1
CVE-2019-10650
CVE-2019-11007
CVE-2019-11008
CVE-2019-9956
CVE    4
CVE-2019-10650
CVE-2019-9956
CVE-2019-11007
CVE-2019-11008
...
CPE    3
cpe:/a:imagemagick:imagemagick
cpe:/a:libMagickCore-7_Q16HDRI6:libMagickCore-7_Q16HDRI6
cpe:/a:libMagickWand-7_Q16HDRI6:libMagickWand-7_Q16HDRI6

© SecPod Technologies