rpm package
opensuse/ImageMagick&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweed
Vulnerabilities (177)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-27770 | Med | 5.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Dec 4, 2020 | Due to a missing check for 0 value of `replace_extent`, it is possible for offset `p` to overflow in SubstituteString(), causing potential impact to application availability. This could be triggered by a crafted input file that is processed by ImageMagick. This flaw affects Image | |
| CVE-2020-27765 | Low | 3.3 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Dec 4, 2020 | A flaw was found in ImageMagick in MagickCore/segment.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to application availability, but could | |
| CVE-2020-27760 | Med | 5.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Dec 3, 2020 | In `GammaImage()` of /MagickCore/enhance.c, depending on the `gamma` value, it's possible to trigger a divide-by-zero condition when a crafted input file is processed by ImageMagick. This could lead to an impact to application availability. The patch uses the `PerceptibleReciproc | |
| CVE-2019-19949 | Cri | 9.1 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Dec 24, 2019 | In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare. | |
| CVE-2019-16710 | Med | 6.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Sep 23, 2019 | ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in MagickCore/memory.c. | |
| CVE-2019-15139 | Med | 6.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Aug 18, 2019 | The XWD image (X Window System window dumping file) parsing component in ImageMagick 7.0.8-41 Q16 allows attackers to cause a denial-of-service (application crash resulting from an out-of-bounds Read) in ReadXWDImage in coders/xwd.c by crafting a corrupted XWD image file, a diffe | |
| CVE-2019-13311 | Med | 6.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of a wand/mogrify.c error. | |
| CVE-2019-13306 | Hig | 7.8 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of off-by-one errors. | |
| CVE-2019-13301 | Med | 6.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has memory leaks in AcquireMagickMemory because of an AnnotateImage error. | |
| CVE-2019-13296 | Med | 6.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has direct memory leaks in AcquireMagickMemory because of an error in CLIListOperatorImages in MagickWand/operation.c for a NULL value. | |
| CVE-2019-13134 | Med | 5.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Jul 1, 2019 | ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadVIFFImage in coders/viff.c. | |
| CVE-2019-12976 | Med | 5.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Jun 26, 2019 | ImageMagick 7.0.8-34 has a memory leak in the ReadPCLImage function in coders/pcl.c. | |
| CVE-2019-11506 | Hig | 8.8 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Apr 24, 2019 | In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. Thi | |
| CVE-2019-11007 | Hig | 8.1 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Apr 8, 2019 | In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap. | |
| CVE-2019-7398 | Hig | 7.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Feb 5, 2019 | In ImageMagick before 7.0.8-25, a memory leak exists in WriteDIBImage in coders/dib.c. | |
| CVE-2018-17966 | Med | 6.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Oct 3, 2018 | ImageMagick 7.0.7-28 has a memory leak vulnerability in WritePDBImage in coders/pdb.c. | |
| CVE-2018-16641 | Med | 6.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Sep 6, 2018 | ImageMagick 7.0.8-6 has a memory leak vulnerability in the TIFFWritePhotoshopLayers function in coders/tiff.c. | |
| CVE-2018-16328 | Cri | 9.8 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Sep 1, 2018 | In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the CheckEventLogging function in MagickCore/log.c. | |
| CVE-2018-14434 | Med | 6.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | Jul 20, 2018 | ImageMagick 7.0.8-4 has a memory leak for a colormap in WriteMPCImage in coders/mpc.c. | |
| CVE-2018-10805 | Med | 6.5 | < 7.1.0.9-1.1 | 7.1.0.9-1.1 | May 8, 2018 | ImageMagick version 7.0.7-28 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c. |
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
Due to a missing check for 0 value of `replace_extent`, it is possible for offset `p` to overflow in SubstituteString(), causing potential impact to application availability. This could be triggered by a crafted input file that is processed by ImageMagick. This flaw affects Image
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
A flaw was found in ImageMagick in MagickCore/segment.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to application availability, but could
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
In `GammaImage()` of /MagickCore/enhance.c, depending on the `gamma` value, it's possible to trigger a divide-by-zero condition when a crafted input file is processed by ImageMagick. This could lead to an impact to application availability. The patch uses the `PerceptibleReciproc
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in MagickCore/memory.c.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
The XWD image (X Window System window dumping file) parsing component in ImageMagick 7.0.8-41 Q16 allows attackers to cause a denial-of-service (application crash resulting from an out-of-bounds Read) in ReadXWDImage in coders/xwd.c by crafting a corrupted XWD image file, a diffe
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of a wand/mogrify.c error.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of off-by-one errors.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick 7.0.8-50 Q16 has memory leaks in AcquireMagickMemory because of an AnnotateImage error.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick 7.0.8-50 Q16 has direct memory leaks in AcquireMagickMemory because of an error in CLIListOperatorImages in MagickWand/operation.c for a NULL value.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadVIFFImage in coders/viff.c.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick 7.0.8-34 has a memory leak in the ReadPCLImage function in coders/pcl.c.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. Thi
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
In ImageMagick before 7.0.8-25, a memory leak exists in WriteDIBImage in coders/dib.c.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick 7.0.7-28 has a memory leak vulnerability in WritePDBImage in coders/pdb.c.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick 7.0.8-6 has a memory leak vulnerability in the TIFFWritePhotoshopLayers function in coders/tiff.c.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the CheckEventLogging function in MagickCore/log.c.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick 7.0.8-4 has a memory leak for a colormap in WriteMPCImage in coders/mpc.c.
- affected < 7.1.0.9-1.1fixed 7.1.0.9-1.1
ImageMagick version 7.0.7-28 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.
Page 8 of 9