File _patchinfo of Package patchinfo.10856

<patchinfo incident="10856">
  <issue tracker="bnc" id="1132054">VUL-0: CVE-2019-11008: GraphicsMagick,ImageMagick: a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c allows remote attackers to cause DOS or other unspecified impact</issue>
  <issue tracker="bnc" id="1132060">VUL-1: CVE-2019-11007: GraphicsMagick,ImageMagick: a heap-based buffer over-read in the ReadMNGImage function of coders/png.c allows attackers to cause a denial of service or information disclosure</issue>
  <issue tracker="bnc" id="1122033">Removing Postscript/EPS/PDF readers from ImageMagick breaks web service at customer</issue>
  <issue tracker="cve" id="2019-10650"/>
  <issue tracker="cve" id="2019-11007"/>
  <issue tracker="cve" id="2019-9956"/>
  <issue tracker="cve" id="2019-11008"/>
  <issue tracker="bnc" id="1131317">VUL-1: CVE-2019-10650: GraphicsMagick,ImageMagick: In ImageMagick 7.0.8-36 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to cause a denial of service or information dis</issue>
  <issue tracker="bnc" id="1130330">VUL-1: CVE-2019-9956: GraphicsMagick,ImageMagick: stack-based buffer overflow in the function PopHexPixel of coders/ps.c</issue>
  <packager>pgajdos</packager>
  <rating>moderate</rating>
  <category>security</category>
  <summary>Security update for ImageMagick</summary>
  <description>This update for ImageMagick fixes the following issues:

Security issues fixed:

- CVE-2019-9956: Fixed a stack-based buffer overflow in PopHexPixel() (bsc#1130330).
- CVE-2019-10650: Fixed a heap-based buffer over-read in WriteTIFFImage() (bsc#1131317).
- CVE-2019-11007: Fixed a heap-based buffer overflow in ReadMNGImage() (bsc#1132060).
- CVE-2019-11008: Fixed a heap-based buffer overflow in WriteXWDImage() (bsc#1132054).

- Added extra -config- packages with Postscript/EPS/PDF readers still enabled.

  Removing the PS decoders is used to harden ImageMagick against security issues within
  ghostscript. Enabling them might impact security. (bsc#1122033)

  These are two packages that can be selected:

  - ImageMagick-config-7-SUSE: This has the PS decoders disabled.
  - ImageMagick-config-7-upstream: This has the PS decoders enabled.

  Depending on your local needs install either one of them. The default is the -SUSE configuration.

</description>
</patchinfo>
openSUSE Build Service is sponsored by