Security update for ImageMagick

This update for ImageMagick fixes the following issues:

Security issues fixed:

- CVE-2019-9956: Fixed a stack-based buffer overflow in PopHexPixel() (bsc#1130330).
- CVE-2019-10650: Fixed a heap-based buffer over-read in WriteTIFFImage() (bsc#1131317).
- CVE-2019-7175: Fixed multiple memory leaks in DecodeImage function (bsc#1128649).
- CVE-2018-20467: Fixed infinite loop in coders/bmp.c (bsc#1120381).
- CVE-2019-7398: Fixed a memory leak in the function WriteDIBImage (bsc#1124365).
- CVE-2019-7397: Fixed a memory leak in the function WritePDFImage (bsc#1124366).
- CVE-2019-7395: Fixed a memory leak in the function WritePSDChannel (bsc#1124368).
- CVE-2018-16413: Fixed a heap-based buffer over-read in PushShortPixel() (bsc#1106989).
- CVE-2018-16412: Fixed a heap-based buffer over-read in ParseImageResourceBlocks() (bsc#1106996).
- CVE-2018-16644: Fixed a regression in dcm coder (bsc#1107609).
- CVE-2019-11007: Fixed a heap-based buffer overflow in ReadMNGImage() (bsc#1132060).
- CVE-2019-11008: Fixed a heap-based buffer overflow in WriteXWDImage() (bsc#1132054).
- CVE-2019-11009: Fixed a heap-based buffer over-read in ReadXWDImage() (bsc#1132053).

- Added extra -config- packages with Postscript/EPS/PDF readers still enabled.

Removing the PS decoders is used to harden ImageMagick against security issues within
ghostscript. Enabling them might impact security. (bsc#1122033)

These are two packages that can be selected:

- ImageMagick-config-6-SUSE: This has the PS decoders disabled.
- ImageMagick-config-6-upstream: This has the PS decoders enabled.

Depending on your local needs install either one of them. The default is the -SUSE configuration.

This update was imported from the SUSE:SLE-12:Update update project.

Fixed bugs
bnc#1131317
VUL-1: CVE-2019-10650: GraphicsMagick,ImageMagick: heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c
bnc#1132060
VUL-1: CVE-2019-11007: GraphicsMagick,ImageMagick: a heap-based buffer over-read in the ReadMNGImage function of coders/png.c allows attackers to cause a denial of service or information disclosure
bnc#1132053
VUL-0: CVE-2019-11009: GraphicsMagick,ImageMagick: a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, allows attackers to cause DOS or information disclosure
bnc#1122033
Removing Postscript/EPS/PDF readers from ImageMagick breaks web service at customer
bnc#1107609
VUL-1: CVE-2018-16644: GraphicsMagick,ImageMagick: missing check for length in the functions ReadDCMImage of coders/dcm.c and ReadPICTImage of coders/pict
bnc#1132054
VUL-0: CVE-2019-11008: GraphicsMagick,ImageMagick: a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c allows remote attackers to cause DOS or other unspecified impact
bnc#1120381
VUL-1: CVE-2018-20467: imagemagick,graphicsmagick: infinite loop and hang in coders/bmp.c
bnc#1124366
VUL-1: CVE-2019-7397: GraphicsMagick,ImageMagick: Memory leak in the WritePDFImage function in coders/pdf.c
bnc#1124365
VUL-1: CVE-2019-7398: GraphicsMagick,ImageMagick: Memory leak in the WriteDIBImage function in coders/dib.c
bnc#1124368
VUL-1: CVE-2019-7395: GraphicsMagick,ImageMagick: Memory leak in the WritePSDChannel function in coders/psd.c
bnc#1106989
VUL-1: CVE-2018-16413: GraphicsMagick,ImageMagick: heap-based buffer over-read in the MagickCore/quantum-private.h PushShortPixel function
bnc#1130330
VUL-1: CVE-2019-9956: GraphicsMagick,ImageMagick: stack-based buffer overflow in the function PopHexPixel of coders/ps.c
bnc#1128649
VUL-1: CVE-2019-7175: ImageMagick: Some memory leaks exist in DecodeImage in coders/pcd.c.
bnc#1106996
VUL-1: CVE-2018-16412: GraphicsMagick,ImageMagick: heap-based buffer over-read in the coders/psd.c ParseImageResourceBlocks function
Selected Binaries
openSUSE Build Service is sponsored by