Security update for GraphicsMagick

This update for GraphicsMagick fixes the following issues:

- security update (core)
* CVE-2018-6799: The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before
1.3.28 allows remote attackers to cause a denial of service (heap overwrite) or possibly have
unspecified other impact via a crafted image file, because a pixel staging area is not used. [boo#1080522]

- security update (png.c)
* CVE-2018-9018: In GraphicsMagick 1.3.28, there is a divide-by-zero in the ReadMNGImage
function of coders/png.c. Remote attackers could leverage this vulnerability to cause a
crash and denial of service via a crafted mng file. [boo#1086773]

- security update (gif.c)
* CVE-2017-18254: An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability
was found in the function WriteGIFImage in coders/gif.c, which allow remote attackers to
cause a denial of service via a crafted file. [boo#1087027]

- security update (pcd.c)
* CVE-2017-18251: An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability
was found in the function ReadPCDImage in coders/pcd.c, which allow remote attackers to cause
a denial of service via a crafted file. [boo#1087037]

* CVE-2017-18229: An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability
was found in the function ReadTIFFImage in coders/tiff.c, which allows attackers to cause a denial of
service via a crafted file, because file size is not properly used to restrict scanline,
strip, and tile allocations. [boo#1085236]

* CVE-2017-11641: GraphicsMagick 1.3.26 has a Memory Leak in the PersistCache function in magick/pixel_cache.c
during writing of Magick Persistent Cache (MPC) files.[boo#1050623]

* CVE-2017-13066: GraphicsMagick 1.3.26 has a memory leak vulnerability in the function CloneImage in
magick/image.c. [boo#1055010]

* CVE-2018-10177: Specially crafted PNG images may have triggered an infinite loop [bsc#1089781]

Fixed bugs
bnc#1050623
VUL-1: CVE-2017-11641: GraphicsMagick: Memory Leak in the PersistCache in magick/pixel_cache.c
bnc#1087027
VUL-1: CVE-2017-18254: GraphicsMagick, ImageMagick: Memory leak in the function WriteGIFImage in coders/gif.c, which allow attackers to cause a denial of service
bnc#1087037
VUL-1: CVE-2017-18251: GraphicsMagick, ImageMagick: Memory leak in the function ReadPCDImage in coders/pcd.c, which allows attackers to cause a denial of service
bnc#1080522
VUL-1: CVE-2018-6799: GraphicsMagick: Heap overwrite in magick/pixel_cache.c:AcquireCacheNexus() can lead to denial of service
bnc#1085236
VUL-1: CVE-2017-18229: GraphicsMagick,ImageMagick: An issue was discovered in GraphicsMagick 1.3.26. An allocation failurevulnerability was found in the function ReadTIFFImage in coders/tiff.c, whichallows attackers to cause a denial of s
bnc#1086773
VUL-1: CVE-2018-9018: GraphicsMagick: a divide-by-zero in the ReadMNGImage function of coders/png.c could lead to denial of service
bnc#1055010
VUL-1: CVE-2017-13066: GraphicsMagick,ImageMagick: GraphicsMagick 1.3.26 has a memory leak vulnerability in the functionCloneImage in magick/image.c.
bnc#1089781
VUL-0: CVE-2018-10177: GraphicsMagick,ImageMagick: In ImageMagick 7.0.7-28, there is an infinite loop in the ReadOneMNGImagefunction of the coders/png.c file. Remote attackers could leverage thisvulnerability to cause a denial of service
Selected Binaries
openSUSE Build Service is sponsored by