/[advisories]/24614.adv
ViewVC logotype

Annotation of /24614.adv

Parent Directory Parent Directory | Revision Log Revision Log


Revision 8444 - (hide annotations) (download)
Wed Apr 10 19:59:55 2019 UTC (5 years ago) by davidwhodgins
File size: 758 byte(s)
Adding security advisory for imagemagick mga#24614
1 davidwhodgins 8444 type: security
2     subject: Updated imagemagick packages fix security vulnerability
3     CVE:
4     - CVE-2019-10649
5     - CVE-2019-10650
6     src:
7     6:
8     core:
9     - imagemagick-6.9.10.36-1.mga6
10     description: |
11     In ImageMagick 7.0.8-36 Q16, there is a memory leak in the function
12     SVGKeyValuePairs of coders/svg.c, which allows an attacker to cause a
13     denial of service via a crafted image file. (CVE-2019-10649)
14    
15     In ImageMagick 7.0.8-36 Q16, there is a heap-based buffer over-read in the
16     function WriteTIFFImage of coders/tiff.c, which allows an attacker to
17     cause a denial of service or information disclosure via a crafted image
18     file. (CVE-2019-10650)
19     references:
20     - https://bugs.mageia.org/show_bug.cgi?id=24614
21     - https://www.imagemagick.org/script/changelog.php

  ViewVC Help
Powered by ViewVC 1.1.30