{"affected":[{"ecosystem_specific":{"binaries":[{"ImageMagick":"6.4.3.6-78.56.1","ImageMagick-devel":"6.4.3.6-78.56.1","libMagick++-devel":"6.4.3.6-78.56.1","libMagick++1":"6.4.3.6-78.56.1","libMagickWand1":"6.4.3.6-78.56.1","libMagickWand1-32bit":"6.4.3.6-78.56.1","perl-PerlMagick":"6.4.3.6-78.56.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 11 SP4","name":"ImageMagick","purl":"pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"6.4.3.6-78.56.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libMagickCore1":"6.4.3.6-78.56.1","libMagickCore1-32bit":"6.4.3.6-78.56.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP4","name":"ImageMagick","purl":"pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"6.4.3.6-78.56.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libMagickCore1":"6.4.3.6-78.56.1","libMagickCore1-32bit":"6.4.3.6-78.56.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP4","name":"ImageMagick","purl":"pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"6.4.3.6-78.56.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for ImageMagick fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2018-11251: Heap-based buffer over-read in ReadSUNImage in coders/sun.c,\n  which allows attackers to cause denial of service (bsc#1094237)\n- CVE-2017-18271: Infinite loop in the function ReadMIFFImage in coders/miff.c,\n  which allows attackers to cause a denial of service (bsc#1094204)\n- CVE-2017-13758: Heap-based buffer overflow in the TracePoint() in\n  MagickCore/draw.c, which allows attackers to cause a denial of\n  service(bsc#1056277)\n- CVE-2018-10805: Fixed several memory leaks in rgb.c, cmyk.c, gray.c, and\n  ycbcr.c (bsc#1095812)\n- CVE-2018-12600: The ReadDIBImage and WriteDIBImage functions allowed\n  attackers to cause an out of bounds write via a crafted file (bsc#1098545)\n- CVE-2018-12599: The ReadBMPImage and WriteBMPImage fucntions allowed\n  attackers to cause an out of bounds write via a crafted file (bsc#1098546)\n- CVE-2018-14434: Fixed a memory leak for a colormap in WriteMPCImage in coders/mpc.c (bsc#1102003)\n- CVE-2018-14435: Fixed a memory leak in DecodeImage in coders/pcd.c (bsc#1102007) \n- CVE-2018-14436: Fixed a memory leak in ReadMIFFImage in coders/miff.c (bsc#1102005)\n- CVE-2018-14437: Fixed a memory leak in parse8BIM in coders/meta.c (bsc#1102004)\n","id":"SUSE-SU-2018:2465-1","modified":"2018-08-21T06:42:49Z","published":"2018-08-21T06:42:49Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20182465-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1056277"},{"type":"REPORT","url":"https://bugzilla.suse.com/1094204"},{"type":"REPORT","url":"https://bugzilla.suse.com/1094237"},{"type":"REPORT","url":"https://bugzilla.suse.com/1095812"},{"type":"REPORT","url":"https://bugzilla.suse.com/1098545"},{"type":"REPORT","url":"https://bugzilla.suse.com/1098546"},{"type":"REPORT","url":"https://bugzilla.suse.com/1102003"},{"type":"REPORT","url":"https://bugzilla.suse.com/1102004"},{"type":"REPORT","url":"https://bugzilla.suse.com/1102005"},{"type":"REPORT","url":"https://bugzilla.suse.com/1102007"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13758"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-18271"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-10805"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-11251"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12599"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12600"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-14434"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-14435"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-14436"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-14437"}],"related":["CVE-2017-13758","CVE-2017-18271","CVE-2018-10805","CVE-2018-11251","CVE-2018-12599","CVE-2018-12600","CVE-2018-14434","CVE-2018-14435","CVE-2018-14436","CVE-2018-14437"],"summary":"Security update for ImageMagick","upstream":["CVE-2017-13758","CVE-2017-18271","CVE-2018-10805","CVE-2018-11251","CVE-2018-12599","CVE-2018-12600","CVE-2018-14434","CVE-2018-14435","CVE-2018-14436","CVE-2018-14437"]}