Bug 1211601 (CVE-2023-2157)

Summary: VUL-0: CVE-2023-2157: GraphicsMagick,ImageMagick: heap overflow vulnerability
Product: [Novell Products] SUSE Security Incidents Reporter: Gabriele Sonnu <gabriele.sonnu>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: rfrohl, security-team
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/367025/
Whiteboard:
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Comment 1 Gabriele Sonnu 2023-05-22 13:32:16 UTC
Only openSUSE:Factory contain the vulnerable code.
Comment 2 Petr Gajdos 2023-05-25 08:33:41 UTC
Thanks Gabriele for evaluation. Also GraphicsMagick does not seem to be affected.

Submitted version 7.1.1-10 into Factory. I believe all fixed.
Comment 3 OBSbugzilla Bot 2023-05-25 10:35:05 UTC
This is an autogenerated message for OBS integration:
This bug (1211601) was mentioned in
https://build.opensuse.org/request/show/1088981 Factory / ImageMagick
Comment 6 Robert Frohl 2024-05-07 11:41:17 UTC
done, closing