Oval Definition:oval:org.opensuse.security:def:56502
Revision Date:2020-12-01Version:1
Title:Security update for ImageMagick (Important)
Description:

This update for ImageMagick fixes the following issues:

* CVE-2017-14989: use-after-free in RenderFreetype in MagickCore/annotate.c could lead to denial of service [bsc#1061254] * CVE-2017-14682: GetNextToken in MagickCore/token.c heap buffer overflow could lead to denial of service [bsc#1060176] * Memory leak in WriteINLINEImage in coders/inline.c could lead to denial of service [bsc#1052744] * CVE-2017-14607: out of bounds read flaw related to ReadTIFFImagehas could possibly disclose potentially sensitive memory [bsc#1059778] * CVE-2017-11640: NULL pointer deref in WritePTIFImage() in coders/tiff.c [bsc#1050632] * CVE-2017-14342: a memory exhaustion vulnerability in ReadWPGImage in coders/wpg.c could lead to denial of service [bsc#1058485] * CVE-2017-14341: Infinite loop in the ReadWPGImage function [bsc#1058637] * CVE-2017-16546: problem in the function ReadWPGImage in coders/wpg.c could lead to denial of service [bsc#1067181] * CVE-2017-16545: The ReadWPGImage function in coders/wpg.c in validation problems could lead to denial of service [bsc#1067184] * CVE-2017-16669: problem in coders/wpg.c could allow remote attackers to cause a denial of service via crafted file [bsc#1067409] * CVE-2017-14175: Lack of End of File check could lead to denial of service [bsc#1057719] * CVE-2017-14138: memory leak vulnerability in ReadWEBPImage in coders/webp.c could lead to denial of service [bsc#1057157] * CVE-2017-13769: denial of service issue in function WriteTHUMBNAILImage in coders/thumbnail.c [bsc#1056432] * CVE-2017-13134: a heap-based buffer over-read was found in thefunction SFWScan in coders/sfw.c, which allows attackers to cause adenial of service via a crafted file. [bsc#1055214] * CVE-2017-15217: memory leak in ReadSGIImage in coders/sgi.c [bsc#1062750] * CVE-2017-11478: ReadOneDJVUImage in coders/djvu.c in ImageMagick allows remote attackers to cause a DoS [bsc#1049796] * CVE-2017-15930: Null Pointer dereference while transfering JPEG scanlines could lead to denial of service [bsc#1066003] * CVE-2017-12983: Heap-based buffer overflow in the ReadSFWImage function in coders/sfw.c inImageMagick 7.0.6-8 allows remote attackers to cause a denial of service [bsc#1054757] * CVE-2017-14531: memory exhaustion issue in ReadSUNImage incoders/sun.c. [bsc#1059666] * CVE-2017-12435: Memory exhaustion in ReadSUNImage in coders/sun.c, which allows attackers to cause denial of service [bsc#1052553] * CVE-2017-12587: User controlable large loop in the ReadPWPImage in coders\pwp.c could lead to denial of service [bsc#1052450] * CVE-2017-11523: ReadTXTImage in coders/txt.c allows remote attackers to cause a denial of service [bsc#1050083] * CVE-2017-14173: unction ReadTXTImage is vulnerable to a integer overflow that could lead to denial of service [bsc#1057729] * CVE-2017-11188: ImageMagick: The ReadDPXImage function in codersdpx.c in ImageMagick 7.0.6-0 has a largeloop vulnerability that can cause CPU exhaustion via a crafted DPX file, relatedto lack of an EOF check. [bnc#1048457] * CVE-2017-11527: ImageMagick: ReadDPXImage in coders/dpx.c allows remote attackers to cause DoS [bnc#1050116] * CVE-2017-11535: GraphicsMagick, ImageMagick: Heap-based buffer over-read in WritePSImage() in coders/ps.c [bnc#1050139] * CVE-2017-11752: ImageMagick: ReadMAGICKImage in coders/magick.c allows to cause DoS [bnc#1051441] * CVE-2017-12140: ImageMagick: ReadDCMImage in codersdcm.c has a ninteger signedness error leading to excessive memory consumption [bnc#1051847] * CVE-2017-12669: ImageMagick: Memory leak in WriteCALSImage in coders/cals.c [bnc#1052689] * CVE-2017-12662: GraphicsMagick, ImageMagick: Memory leak in WritePDFImage in coders/pdf.c [bnc#1052758] * CVE-2017-12644: ImageMagick: Memory leak in ReadDCMImage in codersdcm.c [bnc#1052764] * CVE-2017-14172: ImageMagick: Lack of end of file check in ReadPSImage() could lead to a denial of service [bnc#1057730] * CVE-2017-14733: GraphicsMagick: Heap overflow on ReadRLEImage in coders/rle.c could lead to denial of service [bnc#1060577]

Family:unixClass:patch
Status:Reference(s):1010829
1013659
1013678
1013680
1015119
1027519
1033447
1033448
1039348
1042292
1048457
1049796
1050083
1050116
1050139
1050632
1051441
1051847
1052450
1052553
1052689
1052744
1052758
1052764
1054757
1055214
1056058
1056432
1057157
1057719
1057729
1057730
1058485
1058637
1059666
1059778
1060176
1060577
1061254
1062750
1066003
1066242
1067181
1067184
1067409
1072322
1091107
1097356
1103276
1106923
1108835
1109252
1110445
1111278
1112024
1112852
1113083
1113632
1113665
1118319
1137597
1140747
1159913
1165631
900418
949889
953339
953362
953518
954872
957986
958848
961600
963161
964427
973188
973631
974038
975130
975138
975907
976058
976111
978164
978295
978413
979620
979670
980716
980724
981264
981276
982024
982025
982026
982224
982225
982286
982695
982960
983973
983984
984981
985503
986586
988675
988676
990843
990923
CVE-2010-3609
CVE-2013-0334
CVE-2014-0240
CVE-2014-3672
CVE-2014-8104
CVE-2016-3158
CVE-2016-3159
CVE-2016-3710
CVE-2016-3960
CVE-2016-4001
CVE-2016-4002
CVE-2016-4020
CVE-2016-4037
CVE-2016-4439
CVE-2016-4441
CVE-2016-4453
CVE-2016-4454
CVE-2016-4952
CVE-2016-4962
CVE-2016-4963
CVE-2016-5105
CVE-2016-5106
CVE-2016-5107
CVE-2016-5126
CVE-2016-5238
CVE-2016-5337
CVE-2016-5338
CVE-2016-5403
CVE-2016-6258
CVE-2016-6259
CVE-2016-6351
CVE-2016-8745
CVE-2016-9445
CVE-2016-9446
CVE-2016-9809
CVE-2016-9812
CVE-2016-9813
CVE-2017-1000364
CVE-2017-11188
CVE-2017-11478
CVE-2017-11523
CVE-2017-11527
CVE-2017-11535
CVE-2017-11640
CVE-2017-11752
CVE-2017-12140
CVE-2017-12435
CVE-2017-12587
CVE-2017-12644
CVE-2017-12662
CVE-2017-12669
CVE-2017-12983
CVE-2017-13134
CVE-2017-13769
CVE-2017-14138
CVE-2017-14172
CVE-2017-14173
CVE-2017-14175
CVE-2017-14341
CVE-2017-14342
CVE-2017-14531
CVE-2017-14607
CVE-2017-14682
CVE-2017-14733
CVE-2017-14919
CVE-2017-14989
CVE-2017-15217
CVE-2017-15896
CVE-2017-15930
CVE-2017-16545
CVE-2017-16546
CVE-2017-16669
CVE-2017-3735
CVE-2017-3736
CVE-2017-3738
CVE-2017-5647
CVE-2017-5648
CVE-2018-12389
CVE-2018-12390
CVE-2018-12392
CVE-2018-12393
CVE-2018-12395
CVE-2018-12396
CVE-2018-12397
CVE-2018-15686
CVE-2018-15688
CVE-2018-3646
CVE-2018-5848
CVE-2018-9568
CVE-2019-11477
CVE-2019-11478
CVE-2019-5108
CVE-2020-1749
SUSE-SU-2016:2093-1
SUSE-SU-2016:3297-1
SUSE-SU-2017:1382-1
SUSE-SU-2017:1615-1
SUSE-SU-2017:3388-1
SUSE-SU-2018:0293-1
SUSE-SU-2018:2401-1
SUSE-SU-2018:3749-1
SUSE-SU-2018:3767-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 6
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • gstreamer-plugins-ugly-1.12.5-lp150.1 is installed
  • OR gstreamer-plugins-ugly-lang-1.12.5-lp150.1 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • libxslt-1.1.32-lp151.3.3 is installed
  • OR libxslt-devel-1.1.32-lp151.3.3 is installed
  • OR libxslt-devel-32bit-1.1.32-lp151.3.3 is installed
  • OR libxslt-python-1.1.32-lp151.3.3 is installed
  • OR libxslt-tools-1.1.32-lp151.3.3 is installed
  • OR libxslt1-1.1.32-lp151.3.3 is installed
  • OR libxslt1-32bit-1.1.32-lp151.3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP3 is installed
  • AND Package Information
  • ImageMagick-6.8.8.1-71.17 is installed
  • OR libMagick++-6_Q16-3-6.8.8.1-71.17 is installed
  • OR libMagickCore-6_Q16-1-6.8.8.1-71.17 is installed
  • OR libMagickCore-6_Q16-1-32bit-6.8.8.1-71.17 is installed
  • OR libMagickWand-6_Q16-1-6.8.8.1-71.17 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1 is installed
  • AND Package Information
  • openslp-2.0.0-5 is installed
  • OR openslp-32bit-2.0.0-5 is installed
  • OR openslp-server-2.0.0-5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND Package Information
  • kgraft-patch-3_12_74-60_64_88-default-8-2 is installed
  • OR kgraft-patch-3_12_74-60_64_88-xen-8-2 is installed
  • OR kgraft-patch-SLE12-SP1_Update_27-8-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • openvpn-2.3.8-16.6 is installed
  • OR openvpn-auth-pam-plugin-2.3.8-16.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND ucode-intel-20180703-13.25 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • openssh-7.2p2-74.25 is installed
  • OR openssh-askpass-gnome-7.2p2-74.25 is installed
  • OR openssh-fips-7.2p2-74.25 is installed
  • OR openssh-helpers-7.2p2-74.25 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_74-92_38-default-10-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_13-10-2 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND
  • MozillaFirefox-60.7.2-109.80 is installed
  • OR MozillaFirefox-translations-common-60.7.2-109.80 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND
  • MozillaFirefox-60.7.2-109.80 is installed
  • OR MozillaFirefox-translations-common-60.7.2-109.80 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • evince-3.20.1-5 is installed
  • OR evince-browser-plugin-3.20.1-5 is installed
  • OR evince-lang-3.20.1-5 is installed
  • OR evince-plugin-djvudocument-3.20.1-5 is installed
  • OR evince-plugin-dvidocument-3.20.1-5 is installed
  • OR evince-plugin-pdfdocument-3.20.1-5 is installed
  • OR evince-plugin-psdocument-3.20.1-5 is installed
  • OR evince-plugin-tiffdocument-3.20.1-5 is installed
  • OR evince-plugin-xpsdocument-3.20.1-5 is installed
  • OR libevdocument3-4-3.20.1-5 is installed
  • OR libevview3-3-3.20.1-5 is installed
  • OR nautilus-evince-3.20.1-5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • dbus-1-1.8.22-29.17 is installed
  • OR dbus-1-x11-1.8.22-29.17 is installed
  • OR libdbus-1-3-1.8.22-29.17 is installed
  • OR libdbus-1-3-32bit-1.8.22-29.17 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • krb5-appl-1.0.3-3.3 is installed
  • OR krb5-appl-clients-1.0.3-3.3 is installed
  • OR krb5-appl-servers-1.0.3-3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • fetchmail-6.3.26-12 is installed
  • OR fetchmailconf-6.3.26-12 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 6 is installed
  • AND apache2-mod_wsgi-4.4.13-1 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND nodejs6-6.12.2-11.8 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND squid-3.5.21-26.26 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • crowbar-core-5.0+git.1582968668.1a55c77c5-3.35 is installed
  • OR crowbar-core-branding-upstream-5.0+git.1582968668.1a55c77c5-3.35 is installed
  • OR crowbar-ha-5.0+git.1574286229.e0364c3-3.29 is installed
  • OR crowbar-openstack-5.0+git.1582911795.5081ef1da-4.34 is installed
  • OR crowbar-ui-1.2.0+git.1575896697.a01a3a08-3.15 is installed
  • OR keepalived-2.0.19-3.6 is installed
  • OR mariadb-10.2.31-4.17 is installed
  • OR mariadb-client-10.2.31-4.17 is installed
  • OR mariadb-errormessages-10.2.31-4.17 is installed
  • OR mariadb-galera-10.2.31-4.17 is installed
  • OR mariadb-tools-10.2.31-4.17 is installed
  • OR openstack-cinder-11.2.3~dev23-3.24 is installed
  • OR openstack-cinder-api-11.2.3~dev23-3.24 is installed
  • OR openstack-cinder-backup-11.2.3~dev23-3.24 is installed
  • OR openstack-cinder-doc-11.2.3~dev23-3.24 is installed
  • OR openstack-cinder-scheduler-11.2.3~dev23-3.24 is installed
  • OR openstack-cinder-volume-11.2.3~dev23-3.24 is installed
  • OR openstack-dashboard-12.0.5~dev2-3.23 is installed
  • OR openstack-dashboard-theme-SUSE-2017.2+git.1573629528.6b21fa5-7.14 is installed
  • OR openstack-heat-9.0.8~dev22-3.27 is installed
  • OR openstack-heat-api-9.0.8~dev22-3.27 is installed
  • OR openstack-heat-api-cfn-9.0.8~dev22-3.27 is installed
  • OR openstack-heat-api-cloudwatch-9.0.8~dev22-3.27 is installed
  • OR openstack-heat-doc-9.0.8~dev22-3.27 is installed
  • OR openstack-heat-engine-9.0.8~dev22-3.27 is installed
  • OR openstack-heat-plugin-heat_docker-9.0.8~dev22-3.27 is installed
  • OR openstack-heat-templates-0.0.0+git.1560033670.e3b5a52-3.12 is installed
  • OR openstack-heat-test-9.0.8~dev22-3.27 is installed
  • OR openstack-horizon-plugin-designate-ui-5.0.3~dev2-3.9 is installed
  • OR openstack-horizon-plugin-neutron-lbaas-ui-3.0.3~dev5-3.14 is installed
  • OR openstack-ironic-9.1.8~dev8-3.24 is installed
  • OR openstack-ironic-api-9.1.8~dev8-3.24 is installed
  • OR openstack-ironic-conductor-9.1.8~dev8-3.24 is installed
  • OR openstack-ironic-doc-9.1.8~dev8-3.24 is installed
  • OR openstack-keystone-12.0.4~dev5-5.30 is installed
  • OR openstack-keystone-doc-12.0.4~dev5-5.30 is installed
  • OR openstack-monasca-agent-2.2.5~dev5-3.15 is installed
  • OR openstack-neutron-11.0.9~dev60-3.27 is installed
  • OR openstack-neutron-dhcp-agent-11.0.9~dev60-3.27 is installed
  • OR openstack-neutron-doc-11.0.9~dev60-3.27 is installed
  • OR openstack-neutron-gbp-7.3.1~dev72-3.12 is installed
  • OR openstack-neutron-ha-tool-11.0.9~dev60-3.27 is installed
  • OR openstack-neutron-l3-agent-11.0.9~dev60-3.27 is installed
  • OR openstack-neutron-linuxbridge-agent-11.0.9~dev60-3.27 is installed
  • OR openstack-neutron-macvtap-agent-11.0.9~dev60-3.27 is installed
  • OR openstack-neutron-metadata-agent-11.0.9~dev60-3.27 is installed
  • OR openstack-neutron-metering-agent-11.0.9~dev60-3.27 is installed
  • OR openstack-neutron-openvswitch-agent-11.0.9~dev60-3.27 is installed
  • OR openstack-neutron-server-11.0.9~dev60-3.27 is installed
  • OR openstack-neutron-vsphere-2.0.1~dev133-3.12 is installed
  • OR openstack-neutron-vsphere-doc-2.0.1~dev133-3.12 is installed
  • OR openstack-neutron-vsphere-dvs-agent-2.0.1~dev133-3.12 is installed
  • OR openstack-neutron-vsphere-ovsvapp-agent-2.0.1~dev133-3.12 is installed
  • OR openstack-nova-16.1.9~dev49-3.32 is installed
  • OR openstack-nova-api-16.1.9~dev49-3.32 is installed
  • OR openstack-nova-cells-16.1.9~dev49-3.32 is installed
  • OR openstack-nova-compute-16.1.9~dev49-3.32 is installed
  • OR openstack-nova-conductor-16.1.9~dev49-3.32 is installed
  • OR openstack-nova-console-16.1.9~dev49-3.32 is installed
  • OR openstack-nova-consoleauth-16.1.9~dev49-3.32 is installed
  • OR openstack-nova-doc-16.1.9~dev49-3.32 is installed
  • OR openstack-nova-novncproxy-16.1.9~dev49-3.32 is installed
  • OR openstack-nova-placement-api-16.1.9~dev49-3.32 is installed
  • OR openstack-nova-scheduler-16.1.9~dev49-3.32 is installed
  • OR openstack-nova-serialproxy-16.1.9~dev49-3.32 is installed
  • OR openstack-nova-vncproxy-16.1.9~dev49-3.32 is installed
  • OR openstack-octavia-1.0.6~dev3-4.21 is installed
  • OR openstack-octavia-amphora-agent-1.0.6~dev3-4.21 is installed
  • OR openstack-octavia-amphora-image-0.1.2-3.9 is installed
  • OR openstack-octavia-amphora-image-x86_64-0.1.2-3.9 is installed
  • OR openstack-octavia-api-1.0.6~dev3-4.21 is installed
  • OR openstack-octavia-health-manager-1.0.6~dev3-4.21 is installed
  • OR openstack-octavia-housekeeping-1.0.6~dev3-4.21 is installed
  • OR openstack-octavia-worker-1.0.6~dev3-4.21 is installed
  • OR openstack-resource-agents-1.0+git.1569436425.8b9c49f-3.3 is installed
  • OR openstack-sahara-7.0.5~dev4-3.12 is installed
  • OR openstack-sahara-api-7.0.5~dev4-3.12 is installed
  • OR openstack-sahara-doc-7.0.5~dev4-3.12 is installed
  • OR openstack-sahara-engine-7.0.5~dev4-3.12 is installed
  • OR openstack-trove-8.0.2~dev2-3.12 is installed
  • OR openstack-trove-api-8.0.2~dev2-3.12 is installed
  • OR openstack-trove-conductor-8.0.2~dev2-3.12 is installed
  • OR openstack-trove-doc-8.0.2~dev2-3.12 is installed
  • OR openstack-trove-guestagent-8.0.2~dev2-3.12 is installed
  • OR openstack-trove-taskmanager-8.0.2~dev2-3.12 is installed
  • OR python-cinder-11.2.3~dev23-3.24 is installed
  • OR python-congressclient-1.8.1-3.3 is installed
  • OR python-designateclient-2.7.1-3.3 is installed
  • OR python-designateclient-doc-2.7.1-3.3 is installed
  • OR python-freezegun-0.3.9-1.3 is installed
  • OR python-heat-9.0.8~dev22-3.27 is installed
  • OR python-horizon-12.0.5~dev2-3.23 is installed
  • OR python-horizon-plugin-designate-ui-5.0.3~dev2-3.9 is installed
  • OR python-horizon-plugin-neutron-lbaas-ui-3.0.3~dev5-3.14 is installed
  • OR python-ironic-9.1.8~dev8-3.24 is installed
  • OR python-ironic-lib-2.10.2-3.3 is installed
  • OR python-keystone-12.0.4~dev5-5.30 is installed
  • OR python-monasca-agent-2.2.5~dev5-3.15 is installed
  • OR python-networking-cisco-6.1.1~dev65-3.3 is installed
  • OR python-networking-vsphere-2.0.1~dev133-3.12 is installed
  • OR python-neutron-11.0.9~dev60-3.27 is installed
  • OR python-neutron-gbp-7.3.1~dev72-3.12 is installed
  • OR python-nova-16.1.9~dev49-3.32 is installed
  • OR python-octavia-1.0.6~dev3-4.21 is installed
  • OR python-osc-lib-1.7.1-3.3 is installed
  • OR python-oslo.context-2.17.2-3.3 is installed
  • OR python-oslo.rootwrap-5.9.3-3.3 is installed
  • OR python-oslo.serialization-2.20.3-3.3 is installed
  • OR python-oslo.service-1.25.2-3.3 is installed
  • OR python-sahara-7.0.5~dev4-3.12 is installed
  • OR python-stevedore-1.25.2-3.3 is installed
  • OR python-taskflow-2.14.2-3.3 is installed
  • OR python-trove-8.0.2~dev2-3.12 is installed
  • OR ruby2.1-rubygem-crowbar-client-3.9.1-3.9 is installed
  • OR ruby2.1-rubygem-puma-2.16.0-3.3 is installed
  • OR rubygem-crowbar-client-3.9.1-3.9 is installed
  • OR rubygem-puma-2.16.0-3.3 is installed
  • BACK