Bugzilla – Bug 1202250
VUL-0: CVE-2022-2719: ImageMagick: DoS due to attempted writing of NULL image list
Last modified: 2022-09-08 11:20:55 UTC
rh#2116537 In ImageMagick 7.1.0-29, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image list. This could potentially cause a denial of service. This was fixed in upstream ImageMagick version 7.1.0-30. References: https://github.com/ImageMagick/ImageMagick/commit/716496e6df0add89e9679d6da9c0afca814cfe49 References: https://bugzilla.redhat.com/show_bug.cgi?id=2116537 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-2719
tracking as affected: - SUSE:SLE-15:Update/ImageMagick - SUSE:SLE-15-SP2:Update/ImageMagick - SUSE:SLE-15-SP4:Update/ImageMagick
No testcase found. Submitted for 15sp4,15sp2,15/ImageMagick.
SUSE-SU-2022:2998-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1199350,1202250 CVE References: CVE-2022-2719,CVE-2022-28463 JIRA References: Sources used: openSUSE Leap 15.4 (src): ImageMagick-7.1.0.9-150400.6.6.1 SUSE Linux Enterprise Module for Development Tools 15-SP4 (src): ImageMagick-7.1.0.9-150400.6.6.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP4 (src): ImageMagick-7.1.0.9-150400.6.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:3119-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1202250,1202800 CVE References: CVE-2021-20224,CVE-2022-2719 JIRA References: Sources used: openSUSE Leap 15.4 (src): ImageMagick-7.0.7.34-150200.10.36.1 openSUSE Leap 15.3 (src): ImageMagick-7.0.7.34-150200.10.36.1 SUSE Linux Enterprise Module for Development Tools 15-SP3 (src): ImageMagick-7.0.7.34-150200.10.36.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (src): ImageMagick-7.0.7.34-150200.10.36.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.