rpm package
suse/ImageMagick&distro=SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2
Vulnerabilities (230)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2017-5506 | Hig | 7.8 | < 6.8.8.1-59.1 | 6.8.8.1-59.1 | Mar 24, 2017 | Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a crafted file. | |
| CVE-2016-10146 | Hig | 7.5 | < 6.8.8.1-59.1 | 6.8.8.1-59.1 | Mar 24, 2017 | Multiple memory leaks in the caption and label handling code in ImageMagick allow remote attackers to cause a denial of service (memory consumption) via unspecified vectors. | |
| CVE-2016-10145 | Cri | 9.8 | < 6.8.8.1-59.1 | 6.8.8.1-59.1 | Mar 24, 2017 | Off-by-one error in coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via vectors related to a string copy. | |
| CVE-2016-10144 | Cri | 9.8 | < 6.8.8.1-59.1 | 6.8.8.1-59.1 | Mar 24, 2017 | coders/ipl.c in ImageMagick allows remote attackers to have unspecific impact by leveraging a missing malloc check. | |
| CVE-2016-9556 | Med | 5.5 | < 6.8.8.1-54.1 | 6.8.8.1-54.1 | Mar 23, 2017 | The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file. | |
| CVE-2016-10059 | Hig | 7.8 | < 6.8.8.1-59.1 | 6.8.8.1-59.1 | Mar 23, 2017 | Buffer overflow in coders/tiff.c in ImageMagick before 6.9.4-1 allows remote attackers to cause a denial of service (application crash) or have unspecified other impact via a crafted TIFF file. | |
| CVE-2016-10052 | Hig | 7.8 | < 6.8.8.1-59.1 | 6.8.8.1-59.1 | Mar 23, 2017 | Buffer overflow in the WriteProfile function in coders/jpeg.c in ImageMagick before 6.9.5-6 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file. | |
| CVE-2016-10051 | Hig | 7.8 | < 6.8.8.1-59.1 | 6.8.8.1-59.1 | Mar 23, 2017 | Use-after-free vulnerability in the ReadPWPImage function in coders/pwp.c in ImageMagick 6.9.5-5 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file. | |
| CVE-2016-10050 | Hig | 7.8 | < 6.8.8.1-59.1 | 6.8.8.1-59.1 | Mar 23, 2017 | Heap-based buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.9.4-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE file. | |
| CVE-2016-10049 | Hig | 7.8 | < 6.8.8.1-59.1 | 6.8.8.1-59.1 | Mar 23, 2017 | Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick before 6.9.4-4 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE file. | |
| CVE-2016-10048 | Hig | 7.5 | < 6.8.8.1-59.1 | 6.8.8.1-59.1 | Mar 23, 2017 | Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allows remote attackers to load arbitrary modules via unspecified vectors. | |
| CVE-2016-10046 | Med | 5.5 | < 6.8.8.1-59.1 | 6.8.8.1-59.1 | Mar 23, 2017 | Heap-based buffer overflow in the DrawImage function in magick/draw.c in ImageMagick before 6.9.5-5 allows remote attackers to cause a denial of service (application crash) via a crafted image file. | |
| CVE-2014-9848 | Hig | 7.5 | < 6.8.8.1-54.1 | 6.8.8.1-54.1 | Mar 20, 2017 | Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption). | |
| CVE-2017-6502 | Med | 5.5 | < 6.8.8.1-70.1 | 6.8.8.1-70.1 | Mar 6, 2017 | An issue was discovered in ImageMagick 6.9.7. A specially crafted webp file could lead to a file-descriptor leak in libmagickcore (thus, a DoS). | |
| CVE-2016-10070 | Med | 5.5 | < 6.8.8.1-59.1 | 6.8.8.1-59.1 | Mar 3, 2017 | Heap-based buffer overflow in the CalcMinMax function in coders/mat.c in ImageMagick before 6.9.4-0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted mat file. | |
| CVE-2016-10065 | Hig | 7.8 | < 6.8.8.1-59.1 | 6.8.8.1-59.1 | Mar 3, 2017 | The ReadVIFFImage function in coders/viff.c in ImageMagick before 7.0.1-0 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file. | |
| CVE-2016-10061 | Med | 6.5 | < 6.8.8.1-59.1 | 6.8.8.1-59.1 | Mar 3, 2017 | The ReadGROUP4Image function in coders/tiff.c in ImageMagick before 7.0.1-10 does not check the return value of the fputc function, which allows remote attackers to cause a denial of service (crash) via a crafted image file. | |
| CVE-2016-10071 | Med | 5.5 | < 6.8.8.1-59.1 | 6.8.8.1-59.1 | Mar 2, 2017 | coders/mat.c in ImageMagick before 6.9.4-0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted mat file. | |
| CVE-2016-10069 | Med | 5.5 | < 6.8.8.1-59.1 | 6.8.8.1-59.1 | Mar 2, 2017 | coders/mat.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via a mat file with an invalid number of frames. | |
| CVE-2016-10068 | Med | 5.5 | < 6.8.8.1-59.1 | 6.8.8.1-59.1 | Mar 2, 2017 | The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted XML file. |
- affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1
Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a crafted file.
- affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1
Multiple memory leaks in the caption and label handling code in ImageMagick allow remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
- affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1
Off-by-one error in coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via vectors related to a string copy.
- affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1
coders/ipl.c in ImageMagick allows remote attackers to have unspecific impact by leveraging a missing malloc check.
- affected < 6.8.8.1-54.1fixed 6.8.8.1-54.1
The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file.
- affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1
Buffer overflow in coders/tiff.c in ImageMagick before 6.9.4-1 allows remote attackers to cause a denial of service (application crash) or have unspecified other impact via a crafted TIFF file.
- affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1
Buffer overflow in the WriteProfile function in coders/jpeg.c in ImageMagick before 6.9.5-6 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
- affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1
Use-after-free vulnerability in the ReadPWPImage function in coders/pwp.c in ImageMagick 6.9.5-5 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
- affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1
Heap-based buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.9.4-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE file.
- affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1
Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick before 6.9.4-4 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE file.
- affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1
Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allows remote attackers to load arbitrary modules via unspecified vectors.
- affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1
Heap-based buffer overflow in the DrawImage function in magick/draw.c in ImageMagick before 6.9.5-5 allows remote attackers to cause a denial of service (application crash) via a crafted image file.
- affected < 6.8.8.1-54.1fixed 6.8.8.1-54.1
Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).
- affected < 6.8.8.1-70.1fixed 6.8.8.1-70.1
An issue was discovered in ImageMagick 6.9.7. A specially crafted webp file could lead to a file-descriptor leak in libmagickcore (thus, a DoS).
- affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1
Heap-based buffer overflow in the CalcMinMax function in coders/mat.c in ImageMagick before 6.9.4-0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted mat file.
- affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1
The ReadVIFFImage function in coders/viff.c in ImageMagick before 7.0.1-0 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
- affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1
The ReadGROUP4Image function in coders/tiff.c in ImageMagick before 7.0.1-10 does not check the return value of the fputc function, which allows remote attackers to cause a denial of service (crash) via a crafted image file.
- affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1
coders/mat.c in ImageMagick before 6.9.4-0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted mat file.
- affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1
coders/mat.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via a mat file with an invalid number of frames.
- affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1
The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted XML file.
Page 11 of 12