Bug 1212847 (CVE-2023-3428) - VUL-0: CVE-2023-3428: ImageMagick: heap-buffer-overflow in coders/tiff.c
Summary: VUL-0: CVE-2023-3428: ImageMagick: heap-buffer-overflow in coders/tiff.c
Status: RESOLVED FIXED
Alias: CVE-2023-3428
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/370828/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-3428:3.3:(AV:L...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-06-29 08:56 UTC by Cathy Hu
Modified: 2024-06-07 12:26 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Cathy Hu 2023-06-29 08:56:12 UTC
CVE-2023-3428

A vulnerability was found in ImageMagick <=7.1.1, where heap-based buffer overflow was found in coders/tiff.c.

References:
https://github.com/ImageMagick/ImageMagick/commit/a531d28e31309676ce8168c3b6dbbb5374b78790

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-3428
https://bugzilla.redhat.com/show_bug.cgi?id=2218369
Comment 1 Cathy Hu 2023-06-29 08:56:20 UTC
Affected:
- SUSE:ALP:Source:Standard:1.0/ImageMagick     7.1.1.9
- openSUSE:Factory/ImageMagick                 7.1.1.11

Not Affected:
- SUSE:ALP:Source:Standard:1.0/GraphicsMagick  1.3.40
- SUSE:SLE-15-SP3:Update/GraphicsMagick        1.3.35
- openSUSE:Factory/GraphicsMagick              1.3.40
- SUSE:SLE-11:Update/ImageMagick               6.4.3.6
- SUSE:SLE-12:Update/ImageMagick               6.8.8.1
- SUSE:SLE-15-SP2:Update/ImageMagick           7.0.7.34
- SUSE:SLE-15:Update/ImageMagick               7.0.7.34
- SUSE:SLE-15-SP4:Update/ImageMagick           7.1.0.9
Comment 2 Petr Gajdos 2023-06-29 09:27:43 UTC
Thanks for evaluation.
Submitted into TW,ALP/ImageMagick.

I believe all fixed.
Comment 3 OBSbugzilla Bot 2023-06-29 10:05:03 UTC
This is an autogenerated message for OBS integration:
This bug (1212847) was mentioned in
https://build.opensuse.org/request/show/1095937 Factory / ImageMagick
Comment 4 Petr Gajdos 2023-06-29 10:58:33 UTC
https://build.suse.de/request/show/302447
Comment 6 Andrea Mattiazzo 2024-06-07 12:26:38 UTC
All done, closing.