SUSE SLES11 Security Update : ImageMagick (SUSE-SU-2018:3348-1)

high Nessus Plugin ID 118354

Language:

Synopsis

The remote SUSE host is missing one or more security updates.

Description

This update for ImageMagick fixes the following security issue :

CVE-2017-17934: Prevent memory leaks, related to MSLPopImage and ProcessMSLScript, and associated with mishandling of MSLPushImage calls (bsc#1074170).

CVE-2018-16750: Prevent memory leak in the formatIPTCfromBuffer function (bsc#1108283)

CVE-2018-16749: Added missing NULL check in ReadOneJNGImage that allowed an attacker to cause a denial of service (WriteBlob assertion failure and application exit) via a crafted file (bsc#1108282)

CVE-2018-16413: Prevent heap-based buffer over-read in the PushShortPixel function leading to DoS (bsc#1106989).

CVE-2018-16323: ReadXBMImage left data uninitialized when processing an XBM file that has a negative pixel value. If the affected code was used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data (bsc#1106855)

CVE-2018-16642: The function InsertRow allowed remote attackers to cause a denial of service via a crafted image file due to an out-of-bounds write (bsc#1107616)

CVE-2018-16643: The functions ReadDCMImage, ReadPWPImage, ReadCALSImage, and ReadPICTImage did check the return value of the fputc function, which allowed remote attackers to cause a denial of service via a crafted image file (bsc#1107612)

CVE-2018-16644: Added missing check for length in the functions ReadDCMImage and ReadPICTImage, which allowed remote attackers to cause a denial of service via a crafted image (bsc#1107609)

CVE-2018-16645: Prevent excessive memory allocation issue in the functions ReadBMPImage and ReadDIBImage, which allowed remote attackers to cause a denial of service via a crafted image file (bsc#1107604)

CVE-2018-18024: Fixed an infinite loop in the ReadBMPImage function of the coders/bmp.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file (bsc#1111069)

CVE-2018-18016: Fixed a memory leak in WritePCXImage (bsc#1111072)

CVE-2018-17965: Fixed a memory leak in WriteSGIImage (bsc#1110747)

CVE-2018-17966: Fixed a memory leak in WritePDBImage (bsc#1110746)

Note that Tenable Network Security has extracted the preceding description block directly from the SUSE security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or 'zypper patch'.

Alternatively you can run the command listed for your product :

SUSE Linux Enterprise Software Development Kit 11-SP4:zypper in -t patch sdksp4-ImageMagick-13831=1

SUSE Linux Enterprise Server 11-SP4:zypper in -t patch slessp4-ImageMagick-13831=1

SUSE Linux Enterprise Debuginfo 11-SP4:zypper in -t patch dbgsp4-ImageMagick-13831=1

See Also

https://bugzilla.suse.com/show_bug.cgi?id=1074170

https://bugzilla.suse.com/show_bug.cgi?id=1106855

https://bugzilla.suse.com/show_bug.cgi?id=1106989

https://bugzilla.suse.com/show_bug.cgi?id=1107604

https://bugzilla.suse.com/show_bug.cgi?id=1107609

https://bugzilla.suse.com/show_bug.cgi?id=1107612

https://bugzilla.suse.com/show_bug.cgi?id=1107616

https://bugzilla.suse.com/show_bug.cgi?id=1108282

https://bugzilla.suse.com/show_bug.cgi?id=1108283

https://bugzilla.suse.com/show_bug.cgi?id=1110746

https://bugzilla.suse.com/show_bug.cgi?id=1110747

https://bugzilla.suse.com/show_bug.cgi?id=1111069

https://bugzilla.suse.com/show_bug.cgi?id=1111072

https://www.suse.com/security/cve/CVE-2017-17934/

https://www.suse.com/security/cve/CVE-2018-16323/

https://www.suse.com/security/cve/CVE-2018-16413/

https://www.suse.com/security/cve/CVE-2018-16642/

https://www.suse.com/security/cve/CVE-2018-16643/

https://www.suse.com/security/cve/CVE-2018-16644/

https://www.suse.com/security/cve/CVE-2018-16645/

https://www.suse.com/security/cve/CVE-2018-16749/

https://www.suse.com/security/cve/CVE-2018-16750/

https://www.suse.com/security/cve/CVE-2018-17965/

https://www.suse.com/security/cve/CVE-2018-17966/

https://www.suse.com/security/cve/CVE-2018-18016/

https://www.suse.com/security/cve/CVE-2018-18024/

http://www.nessus.org/u?a462b257

Plugin Details

Severity: High

ID: 118354

File Name: suse_SU-2018-3348-1.nasl

Version: 1.7

Type: local

Agent: unix

Published: 10/24/2018

Updated: 1/19/2021

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:libmagickcore1, cpe:/o:novell:suse_linux:11

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/23/2018

Vulnerability Publication Date: 12/27/2017

Reference Information

CVE: CVE-2017-17934, CVE-2018-16323, CVE-2018-16413, CVE-2018-16642, CVE-2018-16643, CVE-2018-16644, CVE-2018-16645, CVE-2018-16749, CVE-2018-16750, CVE-2018-17965, CVE-2018-17966, CVE-2018-18016, CVE-2018-18024