openSUSE Security Update : GraphicsMagick (openSUSE-2016-1230)

high Nessus Plugin ID 94305
New! Vulnerability Priority Rating (VPR)

Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it is different from CVSS.

VPR Score: 5.9

Synopsis

The remote openSUSE host is missing a security update.

Description

This update for GraphicsMagick fixes the following issues :

- CVE-2016-8684: Mismatch between real filesize and header values (bsc#1005123)

- CVE-2016-8683: Check that filesize is reasonable compared to the header value (bsc#1005127)

- CVE-2016-8682: Stack-buffer read overflow while reading SCT header (bsc#1005125)

- CVE-2016-7996, CVE-2016-7997: WPG Reader Issues (bsc#1003629)

- CVE-2016-7800: 8BIM/8BIMW unsigned underflow leads to heap overflow (bsc#1002422)

- CVE-2016-7537: Out of bound access for corrupted pdb file (bsc#1000711)

- CVE-2016-7533: Wpg file out of bound for corrupted file (bsc#1000707)

- CVE-2016-7531: Pbd file out of bound access (bsc#1000704)

- CVE-2016-7529: out of bound in quantum handling (bsc#1000399)

- CVE-2016-7528: Out of bound access in xcf file coder (bsc#1000434)

- CVE-2016-7527: out of bound access in wpg file coder:
(bsc#1000436)

- CVE-2016-7526: out-of-bounds write in ./MagickCore/pixel-accessor.h (bsc#1000702)

- CVE-2016-7524: AddressSanitizer:heap-buffer-overflow READ of size 1 in meta.c:465 (bsc#1000700)

- CVE-2016-7522: Out of bound access for malformed psd file (bsc#1000698)

- CVE-2016-7519: out-of-bounds read in coders/rle.c (bsc#1000695)

- CVE-2016-7517: out-of-bounds read in coders/pict.c (bsc#1000693)

- CVE-2016-7516: Out of bounds problem in rle, pict, viff and sun files (bsc#1000692)

- CVE-2016-7515: Rle file handling for corrupted file (bsc#1000689)

- CVE-2016-7446 CVE-2016-7447 CVE-2016-7448 CVE-2016-7449:
various issues fixed in 1.3.25 (bsc#999673)

- CVE-2016-7101: SGI Coder Out-Of-Bounds Read Vulnerability (bsc#1001221)

- CVE-2016-6823: BMP Coder Out-Of-Bounds Write Vulnerability (bsc#1001066)

- CVE-2016-5688: Various invalid memory reads in ImageMagick WPG (bsc#985442)

- CVE-2015-8958: Potential DOS in sun file handling due to malformed files (bsc#1000691)

- CVE-2015-8957: Buffer overflow in sun file handling (bsc#1000690)

- Buffer overflows in SIXEL, PDB, MAP, and TIFF coders (bsc#1002209)

- Divide by zero in WriteTIFFImage (bsc#1002206)

Solution

Update the affected GraphicsMagick packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=1000399

https://bugzilla.opensuse.org/show_bug.cgi?id=1000434

https://bugzilla.opensuse.org/show_bug.cgi?id=1000436

https://bugzilla.opensuse.org/show_bug.cgi?id=1000689

https://bugzilla.opensuse.org/show_bug.cgi?id=1000690

https://bugzilla.opensuse.org/show_bug.cgi?id=1000691

https://bugzilla.opensuse.org/show_bug.cgi?id=1000692

https://bugzilla.opensuse.org/show_bug.cgi?id=1000693

https://bugzilla.opensuse.org/show_bug.cgi?id=1000695

https://bugzilla.opensuse.org/show_bug.cgi?id=1000698

https://bugzilla.opensuse.org/show_bug.cgi?id=1000700

https://bugzilla.opensuse.org/show_bug.cgi?id=1000702

https://bugzilla.opensuse.org/show_bug.cgi?id=1000704

https://bugzilla.opensuse.org/show_bug.cgi?id=1000707

https://bugzilla.opensuse.org/show_bug.cgi?id=1000711

https://bugzilla.opensuse.org/show_bug.cgi?id=1001066

https://bugzilla.opensuse.org/show_bug.cgi?id=1001221

https://bugzilla.opensuse.org/show_bug.cgi?id=1002206

https://bugzilla.opensuse.org/show_bug.cgi?id=1002209

https://bugzilla.opensuse.org/show_bug.cgi?id=1002422

https://bugzilla.opensuse.org/show_bug.cgi?id=1003629

https://bugzilla.opensuse.org/show_bug.cgi?id=1005123

https://bugzilla.opensuse.org/show_bug.cgi?id=1005125

https://bugzilla.opensuse.org/show_bug.cgi?id=1005127

https://bugzilla.opensuse.org/show_bug.cgi?id=985442

https://bugzilla.opensuse.org/show_bug.cgi?id=999673

Plugin Details

Severity: High

ID: 94305

File Name: openSUSE-2016-1230.nasl

Version: 2.9

Type: local

Agent: unix

Published: 10/27/2016

Updated: 1/19/2021

Dependencies: ssh_get_info.nasl

Risk Information

Risk Factor: High

VPR Score: 5.9

CVSS v2.0

Base Score: 7.8

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS v3.0

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:GraphicsMagick, p-cpe:/a:novell:opensuse:GraphicsMagick-debuginfo, p-cpe:/a:novell:opensuse:GraphicsMagick-debugsource, p-cpe:/a:novell:opensuse:GraphicsMagick-devel, p-cpe:/a:novell:opensuse:libGraphicsMagick++-Q16-3, p-cpe:/a:novell:opensuse:libGraphicsMagick++-Q16-3-debuginfo, p-cpe:/a:novell:opensuse:libGraphicsMagick++-devel, p-cpe:/a:novell:opensuse:libGraphicsMagick-Q16-3, p-cpe:/a:novell:opensuse:libGraphicsMagick-Q16-3-debuginfo, p-cpe:/a:novell:opensuse:libGraphicsMagick3-config, p-cpe:/a:novell:opensuse:libGraphicsMagickWand-Q16-2, p-cpe:/a:novell:opensuse:libGraphicsMagickWand-Q16-2-debuginfo, p-cpe:/a:novell:opensuse:perl-GraphicsMagick, p-cpe:/a:novell:opensuse:perl-GraphicsMagick-debuginfo, cpe:/o:novell:opensuse:13.2

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Patch Publication Date: 10/26/2016

Reference Information

CVE: CVE-2015-8957, CVE-2015-8958, CVE-2016-5688, CVE-2016-6823, CVE-2016-7101, CVE-2016-7446, CVE-2016-7447, CVE-2016-7448, CVE-2016-7449, CVE-2016-7515, CVE-2016-7516, CVE-2016-7517, CVE-2016-7519, CVE-2016-7522, CVE-2016-7524, CVE-2016-7526, CVE-2016-7527, CVE-2016-7528, CVE-2016-7529, CVE-2016-7531, CVE-2016-7533, CVE-2016-7537, CVE-2016-7800, CVE-2016-7996, CVE-2016-7997, CVE-2016-8682, CVE-2016-8683, CVE-2016-8684