{"affected":[{"ecosystem_specific":{"binaries":[{"ImageMagick":"7.0.7.34-3.9.1","ImageMagick-devel":"7.0.7.34-3.9.1","libMagick++-7_Q16HDRI4":"7.0.7.34-3.9.1","libMagick++-devel":"7.0.7.34-3.9.1","libMagickCore-7_Q16HDRI6":"7.0.7.34-3.9.1","libMagickWand-7_Q16HDRI6":"7.0.7.34-3.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15","name":"ImageMagick","purl":"pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"7.0.7.34-3.9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"perl-PerlMagick":"7.0.7.34-3.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Development Tools 15","name":"ImageMagick","purl":"pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"7.0.7.34-3.9.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for ImageMagick fixes the following issues:\n\nThe following security vulnerabilities were fixed:\n\n- CVE-2018-11625: Fixed heap-based buffer over-read in SetGrayscaleImage in the\n  quantize.c file, which allowed remote attackers to cause buffer over-read via\n  a crafted file. (bsc#1096200)\n- CVE-2018-11624: Fixed a use-after-free issue in the ReadMATImage function in\n  coders/mat.c. (bsc#1096203)\n- CVE-2018-10805: Fixed several memory leaks in bgr.c, rgb.c, cmyk.c, gray.c,\n  and ycbcr.c (bsc#1095812)\n- CVE-2018-12600: The ReadDIBImage and WriteDIBImage functions allowed\n  attackers to cause an out of bounds write via a crafted file (bsc#1098545).\n- CVE-2018-12599: The ReadBMPImage and WriteBMPImage fucntions allowed\n  attackers to cause an out of bounds write via a crafted file (bsc#1098546).\n\nThe following other changes were made:\n\n- Fix -gamma issues in special cases. (bsc#1094745, bsc#1094742)\n","id":"SUSE-SU-2018:2043-1","modified":"2018-07-23T14:02:48Z","published":"2018-07-23T14:02:48Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20182043-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1094742"},{"type":"REPORT","url":"https://bugzilla.suse.com/1094745"},{"type":"REPORT","url":"https://bugzilla.suse.com/1095812"},{"type":"REPORT","url":"https://bugzilla.suse.com/1096200"},{"type":"REPORT","url":"https://bugzilla.suse.com/1096203"},{"type":"REPORT","url":"https://bugzilla.suse.com/1098545"},{"type":"REPORT","url":"https://bugzilla.suse.com/1098546"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-10805"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-11624"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-11625"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12599"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12600"}],"related":["CVE-2018-10805","CVE-2018-11624","CVE-2018-11625","CVE-2018-12599","CVE-2018-12600"],"summary":"Security update for ImageMagick","upstream":["CVE-2018-10805","CVE-2018-11624","CVE-2018-11625","CVE-2018-12599","CVE-2018-12600"]}