Bug 1212847 (CVE-2023-3428)

Summary: VUL-0: CVE-2023-3428: ImageMagick: heap-buffer-overflow in coders/tiff.c
Product: [Novell Products] SUSE Security Incidents Reporter: Cathy Hu <cathy.hu>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Minor    
Priority: P3 - Medium CC: pgajdos, security-team
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/370828/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-3428:3.3:(AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Cathy Hu 2023-06-29 08:56:12 UTC
CVE-2023-3428

A vulnerability was found in ImageMagick <=7.1.1, where heap-based buffer overflow was found in coders/tiff.c.

References:
https://github.com/ImageMagick/ImageMagick/commit/a531d28e31309676ce8168c3b6dbbb5374b78790

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-3428
https://bugzilla.redhat.com/show_bug.cgi?id=2218369
Comment 1 Cathy Hu 2023-06-29 08:56:20 UTC
Affected:
- SUSE:ALP:Source:Standard:1.0/ImageMagick     7.1.1.9
- openSUSE:Factory/ImageMagick                 7.1.1.11

Not Affected:
- SUSE:ALP:Source:Standard:1.0/GraphicsMagick  1.3.40
- SUSE:SLE-15-SP3:Update/GraphicsMagick        1.3.35
- openSUSE:Factory/GraphicsMagick              1.3.40
- SUSE:SLE-11:Update/ImageMagick               6.4.3.6
- SUSE:SLE-12:Update/ImageMagick               6.8.8.1
- SUSE:SLE-15-SP2:Update/ImageMagick           7.0.7.34
- SUSE:SLE-15:Update/ImageMagick               7.0.7.34
- SUSE:SLE-15-SP4:Update/ImageMagick           7.1.0.9
Comment 2 Petr Gajdos 2023-06-29 09:27:43 UTC
Thanks for evaluation.
Submitted into TW,ALP/ImageMagick.

I believe all fixed.
Comment 3 OBSbugzilla Bot 2023-06-29 10:05:03 UTC
This is an autogenerated message for OBS integration:
This bug (1212847) was mentioned in
https://build.opensuse.org/request/show/1095937 Factory / ImageMagick
Comment 4 Petr Gajdos 2023-06-29 10:58:33 UTC
https://build.suse.de/request/show/302447
Comment 6 Andrea Mattiazzo 2024-06-07 12:26:38 UTC
All done, closing.