Bugzilla – Full Text Bug Listing |
Summary: | VUL-1: CVE-2018-6799: GraphicsMagick: Heap overwrite in magick/pixel_cache.c:AcquireCacheNexus() can lead to denial of service | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Victor Pereira <vpereira> |
Component: | Incidents | Assignee: | Security Team bot <security-team> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Minor | ||
Priority: | P4 - Low | CC: | smash_bz |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/199616/ | ||
Whiteboard: | CVSSv3:SUSE:CVE-2018-6799:2.8:(AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L) | ||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Victor Pereira
2018-02-12 07:19:43 UTC
12/GraphicsMagick: code is simlar, considering affected 11/GraphicsMagick: code is different, considering not affected Will submit for: 12/GraphicsMagick (In reply to Petr Gajdos from comment #2) > Will submit for: 12/GraphicsMagick This should have been: Will submit for: 42.3/GraphicsMagick I believe all fixed. This is an autogenerated message for OBS integration: This bug (1080522) was mentioned in https://build.opensuse.org/request/show/600838 42.3 / GraphicsMagick This is an autogenerated message for OBS integration: This bug (1080522) was mentioned in https://build.opensuse.org/request/show/602464 42.3 / GraphicsMagick openSUSE-SU-2018:1123-1: An update that fixes 8 vulnerabilities is now available. Category: security (moderate) Bug References: 1050623,1055010,1080522,1085236,1086773,1087027,1087037,1089781 CVE References: CVE-2017-11641,CVE-2017-13066,CVE-2017-18229,CVE-2017-18251,CVE-2017-18254,CVE-2018-10177,CVE-2018-6799,CVE-2018-9018 Sources used: openSUSE Leap 42.3 (src): GraphicsMagick-1.3.25-87.1 done |