openSUSE Security Update : GraphicsMagick (openSUSE-2016-984)

This script is Copyright (C) 2016-2017 Tenable Network Security, Inc.


Synopsis :

The remote openSUSE host is missing a security update.

Description :

This update for GraphicsMagick fixes the following issues :

- CVE-2014-9805: SEGV due to a corrupted pnm file
(boo#983752)

- CVE-2016-5240: SVG converting issue resulting in DoS
(endless loop) (boo#983309)

- CVE-2016-5241: Arithmetic exception (div by 0) in SVG
conversion (boo#983455)

- CVE-2014-9846: Overflow in rle file (boo#983521)

- CVE-2015-8894: Double free in TGA code (boo#983523)

- CVE-2015-8896: Double free / integer truncation issue
(boo#983533)

- CVE-2014-9807: Double free in pdb coder (boo#983794)

- CVE-2014-9809: SEGV due to corrupted xwd images
(boo#983799)

- CVE-2014-9819: Heap overflow in palm files (boo#984142)

- CVE-2014-9835: Heap overflow in wpf file (boo#984145)

- CVE-2014-9831: Issues handling of corrupted wpg file
(boo#984375)

- CVE-2014-9820: heap overflow in xpm files (boo#984150)

- CVE-2014-9837: Additional PNM sanity checks (boo#984166)

- CVE-2014-9815: Crash on corrupted wpg file (boo#984372)

- CVE-2014-9839: Theoretical out of bound access in via
color maps (boo#984379)

- CVE-2014-9845: Crash due to corrupted dib file
(boo#984394)

- CVE-2014-9817: Heap buffer overflow in pdb file handling
(boo#984400)

- CVE-2014-9853: Memory leak in rle file handling
(boo#984408)

- CVE-2014-9834: Heap overflow in pict file (boo#984436)

- CVE-2016-5688: Various invalid memory reads in
ImageMagick WPG (boo#985442)

- CVE-2016-2317: Multiple vulnerabilities when parsing and
processing SVG files (boo#965853)

- CVE-2016-2318: Multiple vulnerabilities when parsing and
processing SVG files (boo#965853)

See also :

https://bugzilla.opensuse.org/show_bug.cgi?id=965853
https://bugzilla.opensuse.org/show_bug.cgi?id=983309
https://bugzilla.opensuse.org/show_bug.cgi?id=983455
https://bugzilla.opensuse.org/show_bug.cgi?id=983521
https://bugzilla.opensuse.org/show_bug.cgi?id=983523
https://bugzilla.opensuse.org/show_bug.cgi?id=983533
https://bugzilla.opensuse.org/show_bug.cgi?id=983752
https://bugzilla.opensuse.org/show_bug.cgi?id=983794
https://bugzilla.opensuse.org/show_bug.cgi?id=983799
https://bugzilla.opensuse.org/show_bug.cgi?id=984142
https://bugzilla.opensuse.org/show_bug.cgi?id=984145
https://bugzilla.opensuse.org/show_bug.cgi?id=984150
https://bugzilla.opensuse.org/show_bug.cgi?id=984166
https://bugzilla.opensuse.org/show_bug.cgi?id=984372
https://bugzilla.opensuse.org/show_bug.cgi?id=984375
https://bugzilla.opensuse.org/show_bug.cgi?id=984379
https://bugzilla.opensuse.org/show_bug.cgi?id=984394
https://bugzilla.opensuse.org/show_bug.cgi?id=984400
https://bugzilla.opensuse.org/show_bug.cgi?id=984408
https://bugzilla.opensuse.org/show_bug.cgi?id=984436
https://bugzilla.opensuse.org/show_bug.cgi?id=985442

Solution :

Update the affected GraphicsMagick packages.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)