rpm package
opensuse/ImageMagick&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweed
Vulnerabilities (225)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-11506 | Hig | 8.8 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Apr 24, 2019 | In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. Thi | |
| CVE-2019-11007 | Hig | 8.1 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Apr 8, 2019 | In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap. | |
| CVE-2019-7398 | Hig | 7.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Feb 5, 2019 | In ImageMagick before 7.0.8-25, a memory leak exists in WriteDIBImage in coders/dib.c. | |
| CVE-2018-17966 | Med | 6.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Oct 3, 2018 | ImageMagick 7.0.7-28 has a memory leak vulnerability in WritePDBImage in coders/pdb.c. | |
| CVE-2018-16641 | Med | 6.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Sep 6, 2018 | ImageMagick 7.0.8-6 has a memory leak vulnerability in the TIFFWritePhotoshopLayers function in coders/tiff.c. | |
| CVE-2018-16328 | Cri | 9.8 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Sep 1, 2018 | In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the CheckEventLogging function in MagickCore/log.c. | |
| CVE-2018-14434 | Med | 6.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Jul 20, 2018 | ImageMagick 7.0.8-4 has a memory leak for a colormap in WriteMPCImage in coders/mpc.c. | |
| CVE-2018-10805 | Med | 6.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | May 8, 2018 | ImageMagick version 7.0.7-28 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c. | |
| CVE-2018-9135 | Hig | 8.8 | < 7.1.0.8-1.2 | 7.1.0.8-1.2 | Mar 30, 2018 | In ImageMagick 7.0.7-24 Q16, there is a heap-based buffer over-read in IsWEBPImageLossless in coders/webp.c. | |
| CVE-2016-5118 | Cri | 9.8 | < 6.9.6.6-1.1 | 6.9.6.6-1.1 | Jun 10, 2016 | The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename. | |
| CVE-2016-3718 | Med | 5.5 | KEV | < 6.9.6.6-1.1 | 6.9.6.6-1.1 | May 5, 2016 | The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image. |
| CVE-2016-3717 | Med | 5.5 | < 6.9.6.6-1.1 | 6.9.6.6-1.1 | May 5, 2016 | The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image. | |
| CVE-2016-3716 | Low | 3.3 | < 6.9.6.6-1.1 | 6.9.6.6-1.1 | May 5, 2016 | The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image. | |
| CVE-2016-3715 | Med | 5.5 | KEV | < 6.9.6.6-1.1 | 6.9.6.6-1.1 | May 5, 2016 | The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. |
| CVE-2016-3714 | Hig | 8.4 | KEV | < 6.9.6.6-1.1 | 6.9.6.6-1.1 | May 5, 2016 | The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick." |
| CVE-2012-1186 | Med | 5.5 | < 6.9.6.6-1.1 | 6.9.6.6-1.1 | Jun 5, 2012 | Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image. NOTE: this vulnerability exists because of an incomplete fi | |
| CVE-2012-1185 | Hig | 7.8 | < 6.9.6.6-1.1 | 6.9.6.6-1.1 | Jun 5, 2012 | Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in ImageMagick 6.7.5 and earlier allow remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset value in the ResolutionUnit tag in the EXIF | |
| CVE-2012-0248 | Med | 5.5 | < 6.9.6.6-1.1 | 6.9.6.6-1.1 | Jun 5, 2012 | ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF. | |
| CVE-2012-0247 | Hig | 8.8 | < 6.9.6.6-1.1 | 6.9.6.6-1.1 | Jun 5, 2012 | ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0 of an image. | |
| CVE-2007-4987 | — | < 7.1.0.8-1.2 | 7.1.0.8-1.2 | Sep 24, 2007 | Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writing of a '\0' character to an out-of-bounds address. |
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. Thi
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
In ImageMagick before 7.0.8-25, a memory leak exists in WriteDIBImage in coders/dib.c.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick 7.0.7-28 has a memory leak vulnerability in WritePDBImage in coders/pdb.c.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick 7.0.8-6 has a memory leak vulnerability in the TIFFWritePhotoshopLayers function in coders/tiff.c.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the CheckEventLogging function in MagickCore/log.c.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick 7.0.8-4 has a memory leak for a colormap in WriteMPCImage in coders/mpc.c.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick version 7.0.7-28 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.
- affected < 7.1.0.8-1.2fixed 7.1.0.8-1.2
In ImageMagick 7.0.7-24 Q16, there is a heap-based buffer over-read in IsWEBPImageLossless in coders/webp.c.
- affected < 6.9.6.6-1.1fixed 6.9.6.6-1.1
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
- affected < 6.9.6.6-1.1fixed 6.9.6.6-1.1
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
- affected < 6.9.6.6-1.1fixed 6.9.6.6-1.1
The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.
- affected < 6.9.6.6-1.1fixed 6.9.6.6-1.1
The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image.
- affected < 6.9.6.6-1.1fixed 6.9.6.6-1.1
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
- affected < 6.9.6.6-1.1fixed 6.9.6.6-1.1
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."
- affected < 6.9.6.6-1.1fixed 6.9.6.6-1.1
Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image. NOTE: this vulnerability exists because of an incomplete fi
- affected < 6.9.6.6-1.1fixed 6.9.6.6-1.1
Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in ImageMagick 6.7.5 and earlier allow remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset value in the ResolutionUnit tag in the EXIF
- affected < 6.9.6.6-1.1fixed 6.9.6.6-1.1
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.
- affected < 6.9.6.6-1.1fixed 6.9.6.6-1.1
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0 of an image.
- CVE-2007-4987Sep 24, 2007affected < 7.1.0.8-1.2fixed 7.1.0.8-1.2
Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writing of a '\0' character to an out-of-bounds address.
Page 11 of 12