Security update for ImageMagick
This update for ImageMagick fixes the following issues:
- CVE-2021-20309: Division by zero in WaveImage() of MagickCore/visual-effects. (bsc#1184624)
- CVE-2021-20311: Division by zero in sRGBTransformImage() in MagickCore/colorspace.c (bsc#1184626)
- CVE-2021-20312: Integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c (bsc#1184627)
- CVE-2021-20313: Cipher leak when the calculating signatures in TransformSignatureof MagickCore/signature.c (bsc#1184628)
This update was imported from the SUSE:SLE-15-SP2:Update update project.
-
Submitted by
Petr Gajdos (pgajdos)
Fixed bugs
bnc#1184624
VUL-0: CVE-2021-20309: ImageMagick: Division by zero in WaveImage() of MagickCore/visual-effects.c
bnc#1184626
VUL-0: CVE-2021-20311: ImageMagick: Division by zero in sRGBTransformImage() in MagickCore/colorspace.c
bnc#1184628
VUL-1: CVE-2021-20313: ImageMagick: Cipher leak when the calculating signatures in TransformSignatureof MagickCore/signature.c
bnc#1184627
VUL-0: CVE-2021-20312: ImageMagick: Integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c