{"affected":[{"ecosystem_specific":{"binaries":[{"GraphicsMagick":"1.2.5-4.78.16.1","libGraphicsMagick2":"1.2.5-4.78.16.1","perl-GraphicsMagick":"1.2.5-4.78.16.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 11 SP4","name":"GraphicsMagick","purl":"pkg:rpm/suse/GraphicsMagick&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.2.5-4.78.16.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"GraphicsMagick":"1.2.5-4.78.16.1","libGraphicsMagick2":"1.2.5-4.78.16.1"}]},"package":{"ecosystem":"SUSE:Studio Onsite 1.3","name":"GraphicsMagick","purl":"pkg:rpm/suse/GraphicsMagick&distro=SUSE%20Studio%20Onsite%201.3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.2.5-4.78.16.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for GraphicsMagick fixes the following issues:\n\n- CVE-2017-15033: A denial of service attack (memory leak) in ReadYUVImage in coders/yuv.c was fixed (bsc#1061873)\n- CVE-2017-13063: A heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c was fixed (bsc#1055050)\n- CVE-2017-13064: A heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c was fixed (bsc#1055042)\n- CVE-2017-12936: The ReadWMFImage function in coders/wmf.c in GraphicsMagick had a use-after-free issue for data associated with exception reporting.  (bsc#1054598)\n- CVE-2017-13139: The ReadOneMNGImage function in coders/png.c had an out-of-bounds read with the MNG CLIP chunk.  (bsc#1055430)\n- CVE-2017-12937: The ReadSUNImage function in coders/sun.c in GraphicsMagick had a colormap heap-based buffer over-read.  (bsc#1054596)\n- CVE-2017-11534: A Memory Leak in the lite_font_map() function in coders/wmf.c was fixed (bsc#1050135)\n\n","id":"SUSE-SU-2017:3056-1","modified":"2017-11-23T16:15:37Z","published":"2017-11-23T16:15:37Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2017/suse-su-20173056-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1050135"},{"type":"REPORT","url":"https://bugzilla.suse.com/1054596"},{"type":"REPORT","url":"https://bugzilla.suse.com/1054598"},{"type":"REPORT","url":"https://bugzilla.suse.com/1055042"},{"type":"REPORT","url":"https://bugzilla.suse.com/1055050"},{"type":"REPORT","url":"https://bugzilla.suse.com/1055430"},{"type":"REPORT","url":"https://bugzilla.suse.com/1061873"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-11534"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12936"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12937"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13063"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13064"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13139"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-15033"}],"related":["CVE-2017-11534","CVE-2017-12936","CVE-2017-12937","CVE-2017-13063","CVE-2017-13064","CVE-2017-13139","CVE-2017-15033"],"summary":"Security update for GraphicsMagick","upstream":["CVE-2017-11534","CVE-2017-12936","CVE-2017-12937","CVE-2017-13063","CVE-2017-13064","CVE-2017-13139","CVE-2017-15033"]}