rpm package
opensuse/ImageMagick&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweed
Vulnerabilities (225)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-1114 | Hig | 7.1 | < 7.1.1.17-1.1 | 7.1.1.17-1.1 | Apr 29, 2022 | A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion, potentially leading to information disclosure and a denial | |
| CVE-2021-4219 | Med | 5.5 | < 7.1.1.17-1.1 | 7.1.1.17-1.1 | Mar 23, 2022 | A flaw was found in ImageMagick. The vulnerability occurs due to improper use of open functions and leads to a denial of service. This flaw allows an attacker to crash the system. | |
| CVE-2021-20312 | Hig | 7.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | May 11, 2021 | A flaw was found in ImageMagick in versions 7.0.11, where an integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c may trigger undefined behavior via a crafted image file that is submitted by an attacker and processed by an application using ImageMagick. The highest threa | |
| CVE-2021-20246 | Med | 5.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Mar 9, 2021 | A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability. | |
| CVE-2020-27755 | Low | 3.3 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Dec 8, 2020 | in SetImageExtent() of /MagickCore/image.c, an incorrect image depth size can cause a memory leak because the code which checks for the proper image depth size does not reset the size in the event there is an invalid size. The patch resets the depth to a proper size before throwi | |
| CVE-2020-27750 | Med | 5.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Dec 8, 2020 | A flaw was found in ImageMagick in MagickCore/colorspace-private.h and MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned char` and math division | |
| CVE-2020-25666 | Low | 3.3 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Dec 8, 2020 | There are 4 places in HistogramCompare() in MagickCore/histogram.c where an integer overflow is possible during simple math calculations. This occurs in the rgb values and `count` value for a color. The patch uses casts to `ssize_t` type for these calculations, instead of `int`. | |
| CVE-2020-27775 | Low | 3.3 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Dec 4, 2020 | A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type unsigned char. This would most likely lead to an impact to application | |
| CVE-2020-27770 | Med | 5.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Dec 4, 2020 | Due to a missing check for 0 value of `replace_extent`, it is possible for offset `p` to overflow in SubstituteString(), causing potential impact to application availability. This could be triggered by a crafted input file that is processed by ImageMagick. This flaw affects Image | |
| CVE-2020-27765 | Low | 3.3 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Dec 4, 2020 | A flaw was found in ImageMagick in MagickCore/segment.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to application availability, but could | |
| CVE-2020-27760 | Med | 5.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Dec 3, 2020 | In `GammaImage()` of /MagickCore/enhance.c, depending on the `gamma` value, it's possible to trigger a divide-by-zero condition when a crafted input file is processed by ImageMagick. This could lead to an impact to application availability. The patch uses the `PerceptibleReciproc | |
| CVE-2019-19949 | Cri | 9.1 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Dec 24, 2019 | In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare. | |
| CVE-2019-16710 | Med | 6.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Sep 23, 2019 | ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in MagickCore/memory.c. | |
| CVE-2019-15139 | Med | 6.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Aug 18, 2019 | The XWD image (X Window System window dumping file) parsing component in ImageMagick 7.0.8-41 Q16 allows attackers to cause a denial-of-service (application crash resulting from an out-of-bounds Read) in ReadXWDImage in coders/xwd.c by crafting a corrupted XWD image file, a diffe | |
| CVE-2019-13311 | Med | 6.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of a wand/mogrify.c error. | |
| CVE-2019-13306 | Hig | 7.8 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of off-by-one errors. | |
| CVE-2019-13301 | Med | 6.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has memory leaks in AcquireMagickMemory because of an AnnotateImage error. | |
| CVE-2019-13296 | Med | 6.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has direct memory leaks in AcquireMagickMemory because of an error in CLIListOperatorImages in MagickWand/operation.c for a NULL value. | |
| CVE-2019-13134 | Med | 5.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Jul 1, 2019 | ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadVIFFImage in coders/viff.c. | |
| CVE-2019-12976 | Med | 5.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Jun 26, 2019 | ImageMagick 7.0.8-34 has a memory leak in the ReadPCLImage function in coders/pcl.c. |
- affected < 7.1.1.17-1.1fixed 7.1.1.17-1.1
A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion, potentially leading to information disclosure and a denial
- affected < 7.1.1.17-1.1fixed 7.1.1.17-1.1
A flaw was found in ImageMagick. The vulnerability occurs due to improper use of open functions and leads to a denial of service. This flaw allows an attacker to crash the system.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
A flaw was found in ImageMagick in versions 7.0.11, where an integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c may trigger undefined behavior via a crafted image file that is submitted by an attacker and processed by an application using ImageMagick. The highest threa
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
in SetImageExtent() of /MagickCore/image.c, an incorrect image depth size can cause a memory leak because the code which checks for the proper image depth size does not reset the size in the event there is an invalid size. The patch resets the depth to a proper size before throwi
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
A flaw was found in ImageMagick in MagickCore/colorspace-private.h and MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned char` and math division
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
There are 4 places in HistogramCompare() in MagickCore/histogram.c where an integer overflow is possible during simple math calculations. This occurs in the rgb values and `count` value for a color. The patch uses casts to `ssize_t` type for these calculations, instead of `int`.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type unsigned char. This would most likely lead to an impact to application
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
Due to a missing check for 0 value of `replace_extent`, it is possible for offset `p` to overflow in SubstituteString(), causing potential impact to application availability. This could be triggered by a crafted input file that is processed by ImageMagick. This flaw affects Image
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
A flaw was found in ImageMagick in MagickCore/segment.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to application availability, but could
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
In `GammaImage()` of /MagickCore/enhance.c, depending on the `gamma` value, it's possible to trigger a divide-by-zero condition when a crafted input file is processed by ImageMagick. This could lead to an impact to application availability. The patch uses the `PerceptibleReciproc
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in MagickCore/memory.c.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
The XWD image (X Window System window dumping file) parsing component in ImageMagick 7.0.8-41 Q16 allows attackers to cause a denial-of-service (application crash resulting from an out-of-bounds Read) in ReadXWDImage in coders/xwd.c by crafting a corrupted XWD image file, a diffe
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of a wand/mogrify.c error.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of off-by-one errors.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick 7.0.8-50 Q16 has memory leaks in AcquireMagickMemory because of an AnnotateImage error.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick 7.0.8-50 Q16 has direct memory leaks in AcquireMagickMemory because of an error in CLIListOperatorImages in MagickWand/operation.c for a NULL value.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadVIFFImage in coders/viff.c.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick 7.0.8-34 has a memory leak in the ReadPCLImage function in coders/pcl.c.
Page 10 of 12