rpm package
opensuse/GraphicsMagick&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/GraphicsMagick&distro=openSUSE%20Tumbleweed
Vulnerabilities (42)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-61464 | Low | 1.8 | < 1.3.48-1.1 | 1.3.48-1.1 | Jul 15, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which can result in heap memory corruption and denial of service. | |
| CVE-2026-61870 | Low | 2.9 | < 1.3.47-5.1 | 1.3.47-5.1 | Jul 11, 2026 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing specially crafted VIFF images to exhaust available memory and cause denial of service. | |
| CVE-2026-13606 | imp | 8.1 | < 1.3.47-4.1 | 1.3.47-4.1 | Jun 28, 2026 | GraphicsMagick: GraphicsMagick: Memory corruption via crafted Photo CD (PCD) file | |
| CVE-2026-56379 | Hig | 8.1 | < 1.3.48-1.1 | 1.3.48-1.1 | Jun 23, 2026 | ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during render | |
| CVE-2026-46523 | Med | 6.2 | < 1.3.47-3.1 | 1.3.47-3.1 | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, a crafted MSL image can trigger a heap-use-after-free. Versions 7.1.2.23 and 6.9.13-48 fix the issue. | |
| CVE-2026-42050 | Med | 5.5 | < 1.3.46-7.1 | 1.3.46-7.1 | May 11, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-21 and 6.9.13-46, a malicious MIFF file could trigger an overflow when a user opens it in the display tool and right-clicks a tile to invoke the Load / Update menu item. | |
| CVE-2026-33535 | Med | 4.0 | < 1.3.46-6.1 | 1.3.46-6.1 | Mar 26, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, an out-of-bounds write of a zero byte exists in the X11 `display` interaction path that could lead to a crash. Versions 7.1.2-18 and 6.9.13-43 patch the | |
| CVE-2026-30883 | Med | 5.7 | < 1.3.46-3.1 | 1.3.46-3.1 | Mar 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an extremely large image profile could result in a heap overflow when encoding a PNG image. This vulnerability is fixed in 7.1.2-16 and 6.9.13- | |
| CVE-2026-28690 | Med | 6.9 | < 1.3.46-4.1 | 1.3.46-4.1 | Mar 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow vulnerability exists in the MNG encoder. There is a bounds checks missing that could corrupting the stack with attacker | |
| CVE-2026-26284 | Med | 6.5 | < 1.3.46-5.1 | 1.3.46-5.1 | Feb 24, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huffman-coded data from PCD (Photo CD) files. The decoder contains an function that | |
| CVE-2026-25799 | Med | 5.3 | < 1.3.46-2.1 | 1.3.46-2.1 | Feb 24, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a logic error in YUV sampling factor validation allows an invalid sampling factor to bypass checks and trigger a division-by-zero during image | |
| CVE-2025-55154 | Hig | 8.8 | < 1.3.48-2.1 | 1.3.48-2.1 | Aug 13, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (in coders/png.c) are unsafe and can overflow, leading to memory corruption. This issue has b | |
| CVE-2025-32460 | Med | 4.0 | < 1.3.45-3.1 | 1.3.45-3.1 | Apr 9, 2025 | GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call. | |
| CVE-2025-27796 | Med | 4.5 | < 1.3.45-2.1 | 1.3.45-2.1 | Mar 7, 2025 | ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob. | |
| CVE-2025-27795 | Med | 4.3 | < 1.3.45-2.1 | 1.3.45-2.1 | Mar 7, 2025 | ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits. | |
| CVE-2022-1270 | Hig | 7.8 | < 1.3.38-1.1 | 1.3.38-1.1 | Sep 28, 2022 | In GraphicsMagick, a heap buffer overflow was found when parsing MIFF. | |
| CVE-2020-12672 | Hig | 7.5 | < 1.3.36-1.7 | 1.3.36-1.7 | May 6, 2020 | GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c. | |
| CVE-2017-10800 | Med | 5.5 | < 1.3.36-1.7 | 1.3.36-1.7 | Jul 3, 2017 | When GraphicsMagick 1.3.25 processes a MATLAB image in coders/mat.c, it can lead to a denial of service (OOM) in ReadMATImage() if the size specified for a MAT Object is larger than the actual amount of data. | |
| CVE-2017-10799 | Med | 5.5 | < 1.3.36-1.7 | 1.3.36-1.7 | Jul 3, 2017 | When GraphicsMagick 1.3.25 processes a DPX image (with metadata indicating a large width) in coders/dpx.c, a denial of service (OOM) can occur in ReadDPXImage(). | |
| CVE-2017-10794 | Med | 5.5 | < 1.3.36-1.7 | 1.3.36-1.7 | Jul 2, 2017 | When GraphicsMagick 1.3.25 processes an RGB TIFF picture (with metadata indicating a single sample per pixel) in coders/tiff.c, a buffer overflow occurs, related to QuantumTransferMode. |
- affected < 1.3.48-1.1fixed 1.3.48-1.1
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which can result in heap memory corruption and denial of service.
- affected < 1.3.47-5.1fixed 1.3.47-5.1
ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing specially crafted VIFF images to exhaust available memory and cause denial of service.
- affected < 1.3.47-4.1fixed 1.3.47-4.1
GraphicsMagick: GraphicsMagick: Memory corruption via crafted Photo CD (PCD) file
- affected < 1.3.48-1.1fixed 1.3.48-1.1
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during render
- affected < 1.3.47-3.1fixed 1.3.47-3.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, a crafted MSL image can trigger a heap-use-after-free. Versions 7.1.2.23 and 6.9.13-48 fix the issue.
- affected < 1.3.46-7.1fixed 1.3.46-7.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-21 and 6.9.13-46, a malicious MIFF file could trigger an overflow when a user opens it in the display tool and right-clicks a tile to invoke the Load / Update menu item.
- affected < 1.3.46-6.1fixed 1.3.46-6.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, an out-of-bounds write of a zero byte exists in the X11 `display` interaction path that could lead to a crash. Versions 7.1.2-18 and 6.9.13-43 patch the
- affected < 1.3.46-3.1fixed 1.3.46-3.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an extremely large image profile could result in a heap overflow when encoding a PNG image. This vulnerability is fixed in 7.1.2-16 and 6.9.13-
- affected < 1.3.46-4.1fixed 1.3.46-4.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow vulnerability exists in the MNG encoder. There is a bounds checks missing that could corrupting the stack with attacker
- affected < 1.3.46-5.1fixed 1.3.46-5.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huffman-coded data from PCD (Photo CD) files. The decoder contains an function that
- affected < 1.3.46-2.1fixed 1.3.46-2.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a logic error in YUV sampling factor validation allows an invalid sampling factor to bypass checks and trigger a division-by-zero during image
- affected < 1.3.48-2.1fixed 1.3.48-2.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (in coders/png.c) are unsafe and can overflow, leading to memory corruption. This issue has b
- affected < 1.3.45-3.1fixed 1.3.45-3.1
GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.
- affected < 1.3.45-2.1fixed 1.3.45-2.1
ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob.
- affected < 1.3.45-2.1fixed 1.3.45-2.1
ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.
- affected < 1.3.38-1.1fixed 1.3.38-1.1
In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.
- affected < 1.3.36-1.7fixed 1.3.36-1.7
GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.
- affected < 1.3.36-1.7fixed 1.3.36-1.7
When GraphicsMagick 1.3.25 processes a MATLAB image in coders/mat.c, it can lead to a denial of service (OOM) in ReadMATImage() if the size specified for a MAT Object is larger than the actual amount of data.
- affected < 1.3.36-1.7fixed 1.3.36-1.7
When GraphicsMagick 1.3.25 processes a DPX image (with metadata indicating a large width) in coders/dpx.c, a denial of service (OOM) can occur in ReadDPXImage().
- affected < 1.3.36-1.7fixed 1.3.36-1.7
When GraphicsMagick 1.3.25 processes an RGB TIFF picture (with metadata indicating a single sample per pixel) in coders/tiff.c, a buffer overflow occurs, related to QuantumTransferMode.
Page 1 of 3