Security update for GraphicsMagick

This update for GraphicsMagick fixes the following issues:

- CVE-2016-8684: Mismatch between real filesize and header values (bsc#1005123)
- CVE-2016-8683: Check that filesize is reasonable compared to the header value (bsc#1005127)
- CVE-2016-8682: Stack-buffer read overflow while reading SCT header (bsc#1005125)
- CVE-2016-7996, CVE-2016-7997: WPG Reader Issues (bsc#1003629)
- CVE-2016-7800: 8BIM/8BIMW unsigned underflow leads to heap overflow (bsc#1002422)
- CVE-2016-7537: Out of bound access for corrupted pdb file (bsc#1000711)
- CVE-2016-7533: Wpg file out of bound for corrupted file (bsc#1000707)
- CVE-2016-7531: Pbd file out of bound access (bsc#1000704)
- CVE-2016-7529: out of bound in quantum handling (bsc#1000399)
- CVE-2016-7528: Out of bound access in xcf file coder (bsc#1000434)
- CVE-2016-7527: out of bound access in wpg file coder: (bsc#1000436)
- CVE-2016-7526: out-of-bounds write in ./MagickCore/pixel-accessor.h (bsc#1000702)
- CVE-2016-7524: AddressSanitizer:heap-buffer-overflow READ of size 1 in meta.c:465 (bsc#1000700)
- CVE-2016-7522: Out of bound access for malformed psd file (bsc#1000698)
- CVE-2016-7519: out-of-bounds read in coders/rle.c (bsc#1000695)
- CVE-2016-7517: out-of-bounds read in coders/pict.c (bsc#1000693)
- CVE-2016-7516: Out of bounds problem in rle, pict, viff and sun files (bsc#1000692)
- CVE-2016-7515: Rle file handling for corrupted file (bsc#1000689)
- CVE-2016-7446 CVE-2016-7447 CVE-2016-7448 CVE-2016-7449: various issues fixed in 1.3.25 (bsc#999673)
- CVE-2016-7101: SGI Coder Out-Of-Bounds Read Vulnerability (bsc#1001221)
- CVE-2016-6823: BMP Coder Out-Of-Bounds Write Vulnerability (bsc#1001066)
- CVE-2016-5688: Various invalid memory reads in ImageMagick WPG (bsc#985442)
- CVE-2015-8958: Potential DOS in sun file handling due to malformed files (bsc#1000691)
- CVE-2015-8957: Buffer overflow in sun file handling (bsc#1000690)
- Buffer overflows in SIXEL, PDB, MAP, and TIFF coders (bsc#1002209)
- Divide by zero in WriteTIFFImage (bsc#1002206)

Fixed bugs
bnc#1005127
CVE-2016-8683: GraphicsMagick: Check that filesize is reasonable compared to the header value
bnc#1005125
CVE-2016-8682: GraphicsMagick: Stack-buffer read overflow while reading SCT header
bnc#1005123
GraphicsMagick: CVE-2016-8684: Mismatch between real filesize and header values
bnc#1003629
CVE-2016-7996, CVE-2016-7997: GraphicsMagick: WPG Reader Issues
bnc#1002422
CVE-2016-7800: ImageMagick, GraphicsMagick: 8BIM/8BIMW unsigned underflow leads to heap overflow
bnc#1002209
Buffer overflows in SIXEL, PDB, MAP, and TIFF coders
bnc#1002206
Divide by zero in WriteTIFFImage
bnc#1001221
CVE-2016-7101: ImageMagick,GraphicsMagick: SGI Coder Out-Of-Bounds Read Vulnerability
bnc#1001066
CVE-2016-6823: ImageMagick,GraphicsMagick: BMP Coder Out-Of-Bounds Write Vulnerability
bnc#1000711
CVE-2016-7537: Out of bound access for corrupted pdb file
bnc#1000707
CVE-2016-7533: Wpg file out of bound for corrupted file
bnc#1000704
CVE-2016-7531: Pbd file out of bound access
bnc#1000702
CVE-2016-7526: out-of-bounds write in ./MagickCore/pixel-accessor.h
bnc#1000700
CVE-2016-7524: AddressSanitizer:heap-buffer-overflow READ of size 1 in meta.c:465
bnc#1000698
CVE-2016-7522: Out of bound access for malformed psd file
bnc#1000695
CVE-2016-7519: out-of-bounds read in coders/rle.c
bnc#1000693
CVE-2016-7517: out-of-bounds read in coders/pict.c
bnc#1000692
CVE-2016-7516: Out of bounds problem in rle, pict, viff and sun files
bnc#1000691
CVE-2015-8958: Potential DOS in sun file handling due to malformed files
bnc#1000690
CVE-2015-8957: Buffer overflow in sun file handling
bnc#1000689
CVE-2016-7515: Rle file handling for corrupted file
bnc#1000436
CVE-2016-7527: ImageMagick: out of bound access in wpg file coder
bnc#1000434
CVE-2016-7528: out of bound access in xcf file coder
bnc#1000399
CVE-2016-7529: out of bound in quantum handling
bnc#999673
CVE-2016-7446 CVE-2016-7447 CVE-2016-7448 CVE-2016-7449: GraphicsMagick: various issues fixed in 1.3.25
bnc#985442
CVE-2016-5688: GraphicsMagick, Re: Various invalid memory reads in ImageMagick WPG
Selected Binaries
openSUSE Build Service is sponsored by