Bugzilla – Bug 1059663
VUL-0: CVE-2017-14532: ImageMagick: NULL Pointer Dereference in TIFFIgnoreTags incoders/tiff.c. could lead to remote denial of service
Last modified: 2017-10-16 22:41:18 UTC
CVE-2017-14532 ImageMagick 7.0.7-0 has a NULL Pointer Dereference in TIFFIgnoreTags in coders/tiff.c. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-14532 http://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-14532.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14532 https://github.com/ImageMagick/ImageMagick/issues/719
I wasn't able to find the function TIFFIgnoreTags in our enteprise codestreams. Therefore I think we are not affected. I couldn't find any reproducer.
considering sle not affected after last comment.
ImageMagick: factory has the patch already, 12 and older is not affected (comment 1) GraphicsMagick: 12 not affected (comment 1) 42.2, 42.3 and devel affected mercurial not affected (have the check already)
Packages for 42.3 and 42.2 submitted. Tumbleweed will be fixed trough version update.
This is an autogenerated message for OBS integration: This bug (1059663) was mentioned in https://build.opensuse.org/request/show/531714 42.2 / GraphicsMagick https://build.opensuse.org/request/show/531715 42.3 / GraphicsMagick
This is an autogenerated message for OBS integration: This bug (1059663) was mentioned in https://build.opensuse.org/request/show/532233 42.2 / GraphicsMagick https://build.opensuse.org/request/show/532234 42.3 / GraphicsMagick
This is an autogenerated message for OBS integration: This bug (1059663) was mentioned in https://build.opensuse.org/request/show/532710 42.3 / GraphicsMagick https://build.opensuse.org/request/show/532711 42.2 / GraphicsMagick
release for Leap, done
openSUSE-SU-2017:2735-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1059663,1061873 CVE References: CVE-2017-14532,CVE-2017-15033 Sources used: openSUSE Leap 42.3 (src): GraphicsMagick-1.3.25-27.1 openSUSE Leap 42.2 (src): GraphicsMagick-1.3.25-11.27.1