VYPR

rpm package

suse/ImageMagick&distro=SUSE Linux Enterprise Workstation Extension 12 SP2

pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP2

Vulnerabilities (230)

  • CVE-2017-5506HigMar 24, 2017
    affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1

    Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a crafted file.

  • CVE-2016-10146HigMar 24, 2017
    affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1

    Multiple memory leaks in the caption and label handling code in ImageMagick allow remote attackers to cause a denial of service (memory consumption) via unspecified vectors.

  • CVE-2016-10145CriMar 24, 2017
    affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1

    Off-by-one error in coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via vectors related to a string copy.

  • CVE-2016-10144CriMar 24, 2017
    affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1

    coders/ipl.c in ImageMagick allows remote attackers to have unspecific impact by leveraging a missing malloc check.

  • CVE-2016-9556MedMar 23, 2017
    affected < 6.8.8.1-54.1fixed 6.8.8.1-54.1

    The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file.

  • CVE-2016-10059HigMar 23, 2017
    affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1

    Buffer overflow in coders/tiff.c in ImageMagick before 6.9.4-1 allows remote attackers to cause a denial of service (application crash) or have unspecified other impact via a crafted TIFF file.

  • CVE-2016-10052HigMar 23, 2017
    affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1

    Buffer overflow in the WriteProfile function in coders/jpeg.c in ImageMagick before 6.9.5-6 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.

  • CVE-2016-10051HigMar 23, 2017
    affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1

    Use-after-free vulnerability in the ReadPWPImage function in coders/pwp.c in ImageMagick 6.9.5-5 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.

  • CVE-2016-10050HigMar 23, 2017
    affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1

    Heap-based buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.9.4-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE file.

  • CVE-2016-10049HigMar 23, 2017
    affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1

    Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick before 6.9.4-4 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE file.

  • CVE-2016-10048HigMar 23, 2017
    affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1

    Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allows remote attackers to load arbitrary modules via unspecified vectors.

  • CVE-2016-10046MedMar 23, 2017
    affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1

    Heap-based buffer overflow in the DrawImage function in magick/draw.c in ImageMagick before 6.9.5-5 allows remote attackers to cause a denial of service (application crash) via a crafted image file.

  • CVE-2014-9848HigMar 20, 2017
    affected < 6.8.8.1-54.1fixed 6.8.8.1-54.1

    Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).

  • CVE-2017-6502MedMar 6, 2017
    affected < 6.8.8.1-70.1fixed 6.8.8.1-70.1

    An issue was discovered in ImageMagick 6.9.7. A specially crafted webp file could lead to a file-descriptor leak in libmagickcore (thus, a DoS).

  • CVE-2016-10070MedMar 3, 2017
    affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1

    Heap-based buffer overflow in the CalcMinMax function in coders/mat.c in ImageMagick before 6.9.4-0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted mat file.

  • CVE-2016-10065HigMar 3, 2017
    affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1

    The ReadVIFFImage function in coders/viff.c in ImageMagick before 7.0.1-0 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.

  • CVE-2016-10061MedMar 3, 2017
    affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1

    The ReadGROUP4Image function in coders/tiff.c in ImageMagick before 7.0.1-10 does not check the return value of the fputc function, which allows remote attackers to cause a denial of service (crash) via a crafted image file.

  • CVE-2016-10071MedMar 2, 2017
    affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1

    coders/mat.c in ImageMagick before 6.9.4-0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted mat file.

  • CVE-2016-10069MedMar 2, 2017
    affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1

    coders/mat.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via a mat file with an invalid number of frames.

  • CVE-2016-10068MedMar 2, 2017
    affected < 6.8.8.1-59.1fixed 6.8.8.1-59.1

    The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted XML file.

Page 11 of 12