openSUSE Security Update : GraphicsMagick (openSUSE-2016-825)

High Nessus Plugin ID 91945

New! Vulnerability Priority Rating (VPR)

Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it's different from CVSS.

VPR Score: 5.9

Synopsis

The remote openSUSE host is missing a security update.

Description

GraphicsMagick was updated to fix 37 security issues.

These security issues were fixed :

- CVE-2014-9810: SEGV in dpx file handler (bsc#983803).

- CVE-2014-9811: Crash in xwd file handler (bsc#984032).

- CVE-2014-9813: Crash on corrupted viff file (bsc#984035).

- CVE-2014-9814: NULL pointer dereference in wpg file handling (bsc#984193).

- CVE-2014-9815: Crash on corrupted wpg file (bsc#984372).

- CVE-2014-9816: Out of bound access in viff image (bsc#984398).

- CVE-2014-9817: Heap buffer overflow in pdb file handling (bsc#984400).

- CVE-2014-9818: Out of bound access on malformed sun file (bsc#984181).

- CVE-2014-9819: Heap overflow in palm files (bsc#984142).

- CVE-2014-9830: Handling of corrupted sun file (bsc#984135).

- CVE-2014-9831: Handling of corrupted wpg file (bsc#984375).

- CVE-2014-9837: Additional PNM sanity checks (bsc#984166).

- CVE-2014-9834: Heap overflow in pict file (bsc#984436).

- CVE-2014-9853: Memory leak in rle file handling (bsc#984408).

- CVE-2015-8903: Denial of service (cpu) in vicar (bsc#983259).

- CVE-2015-8901: MIFF file DoS (endless loop) (bsc#983234).

- CVE-2016-5688: Various invalid memory reads in ImageMagick WPG (bsc#985442).

- CVE-2015-8894: Double free in coders/tga.c:221 (bsc#983523).

- CVE-2015-8896: Double free / integer truncation issue in coders/pict.c:2000 (bsc#983533).

- CVE-2014-9807: Double free in pdb coder. (bsc#983794).

- CVE-2014-9828: corrupted (too many colors) psd file (bsc#984028).

- CVE-2014-9805: SEGV due to a corrupted pnm file.
(bsc#983752).

- CVE-2014-9808: SEGV due to corrupted dpc images.
(bsc#983796).

- CVE-2014-9820: Heap overflow in xpm files (bsc#984150).

- CVE-2014-9839: Theoretical out of bound access in magick/colormap-private.h (bsc#984379).

- CVE-2014-9809: SEGV due to corrupted xwd images.
(bsc#983799).

- CVE-2016-5240: SVG converting issue resulting in DoS (endless loop) (bsc#983309).

- CVE-2014-9840: Out of bound access in palm file (bsc#984433).

- CVE-2014-9847: Incorrect handling of 'previous' image in the JNG decoder (bsc#984144).

- CVE-2016-5241: Arithmetic exception (div by 0) in SVG conversion (bsc#983455).

- CVE-2014-9845: Crash due to corrupted dib file (bsc#984394).

- CVE-2014-9844: Out of bound issue in rle file (bsc#984373).

- CVE-2014-9835: Heap overflow in wpf file (bsc#984145).

- CVE-2014-9829: Out of bound access in sun file (bsc#984409).

- CVE-2014-9846: Added checks to prevent overflow in rle file (bsc#983521).

- CVE-2016-2317: Multiple vulnerabilities when parsing and processing SVG files (bsc#965853).

- CVE-2016-2318: Multiple vulnerabilities when parsing and processing SVG files (bsc#965853).

Solution

Update the affected GraphicsMagick packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=965853

https://bugzilla.opensuse.org/show_bug.cgi?id=983234

https://bugzilla.opensuse.org/show_bug.cgi?id=983259

https://bugzilla.opensuse.org/show_bug.cgi?id=983309

https://bugzilla.opensuse.org/show_bug.cgi?id=983455

https://bugzilla.opensuse.org/show_bug.cgi?id=983521

https://bugzilla.opensuse.org/show_bug.cgi?id=983523

https://bugzilla.opensuse.org/show_bug.cgi?id=983533

https://bugzilla.opensuse.org/show_bug.cgi?id=983752

https://bugzilla.opensuse.org/show_bug.cgi?id=983794

https://bugzilla.opensuse.org/show_bug.cgi?id=983796

https://bugzilla.opensuse.org/show_bug.cgi?id=983799

https://bugzilla.opensuse.org/show_bug.cgi?id=983803

https://bugzilla.opensuse.org/show_bug.cgi?id=984028

https://bugzilla.opensuse.org/show_bug.cgi?id=984032

https://bugzilla.opensuse.org/show_bug.cgi?id=984035

https://bugzilla.opensuse.org/show_bug.cgi?id=984135

https://bugzilla.opensuse.org/show_bug.cgi?id=984142

https://bugzilla.opensuse.org/show_bug.cgi?id=984144

https://bugzilla.opensuse.org/show_bug.cgi?id=984145

https://bugzilla.opensuse.org/show_bug.cgi?id=984150

https://bugzilla.opensuse.org/show_bug.cgi?id=984166

https://bugzilla.opensuse.org/show_bug.cgi?id=984181

https://bugzilla.opensuse.org/show_bug.cgi?id=984193

https://bugzilla.opensuse.org/show_bug.cgi?id=984372

https://bugzilla.opensuse.org/show_bug.cgi?id=984373

https://bugzilla.opensuse.org/show_bug.cgi?id=984375

https://bugzilla.opensuse.org/show_bug.cgi?id=984379

https://bugzilla.opensuse.org/show_bug.cgi?id=984394

https://bugzilla.opensuse.org/show_bug.cgi?id=984398

https://bugzilla.opensuse.org/show_bug.cgi?id=984400

https://bugzilla.opensuse.org/show_bug.cgi?id=984408

https://bugzilla.opensuse.org/show_bug.cgi?id=984409

https://bugzilla.opensuse.org/show_bug.cgi?id=984433

https://bugzilla.opensuse.org/show_bug.cgi?id=984436

https://bugzilla.opensuse.org/show_bug.cgi?id=985442

Plugin Details

Severity: High

ID: 91945

File Name: openSUSE-2016-825.nasl

Version: 2.6

Type: local

Agent: unix

Published: 2016/07/05

Updated: 2021/01/19

Dependencies: 12634

Risk Information

Risk Factor: High

VPR Score: 5.9

CVSS v2.0

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS v3.0

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:GraphicsMagick, p-cpe:/a:novell:opensuse:GraphicsMagick-debuginfo, p-cpe:/a:novell:opensuse:GraphicsMagick-debugsource, p-cpe:/a:novell:opensuse:GraphicsMagick-devel, p-cpe:/a:novell:opensuse:libGraphicsMagick++-Q16-3, p-cpe:/a:novell:opensuse:libGraphicsMagick++-Q16-3-debuginfo, p-cpe:/a:novell:opensuse:libGraphicsMagick++-devel, p-cpe:/a:novell:opensuse:libGraphicsMagick-Q16-3, p-cpe:/a:novell:opensuse:libGraphicsMagick-Q16-3-debuginfo, p-cpe:/a:novell:opensuse:libGraphicsMagick3-config, p-cpe:/a:novell:opensuse:libGraphicsMagickWand-Q16-2, p-cpe:/a:novell:opensuse:libGraphicsMagickWand-Q16-2-debuginfo, p-cpe:/a:novell:opensuse:perl-GraphicsMagick, p-cpe:/a:novell:opensuse:perl-GraphicsMagick-debuginfo, cpe:/o:novell:opensuse:13.2

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Patch Publication Date: 2016/07/01

Reference Information

CVE: CVE-2014-9805, CVE-2014-9807, CVE-2014-9808, CVE-2014-9809, CVE-2014-9810, CVE-2014-9811, CVE-2014-9813, CVE-2014-9814, CVE-2014-9815, CVE-2014-9816, CVE-2014-9817, CVE-2014-9818, CVE-2014-9819, CVE-2014-9820, CVE-2014-9828, CVE-2014-9829, CVE-2014-9830, CVE-2014-9831, CVE-2014-9834, CVE-2014-9835, CVE-2014-9837, CVE-2014-9839, CVE-2014-9840, CVE-2014-9844, CVE-2014-9845, CVE-2014-9846, CVE-2014-9847, CVE-2014-9853, CVE-2015-8894, CVE-2015-8896, CVE-2015-8901, CVE-2015-8903, CVE-2016-2317, CVE-2016-2318, CVE-2016-5240, CVE-2016-5241, CVE-2016-5688