Bugzilla – Bug 1043289
VUL-0: CVE-2017-9501: ImageMagick: in version 7.0.5-7 Q16, an assertion failure could cause a denial of service via a crafted file.
Last modified: 2017-08-28 14:54:49 UTC
CVE-2017-9501 In ImageMagick 7.0.5-7 Q16, an assertion failure was found in the function LockSemaphoreInfo, which allows attackers to cause a denial of service via a crafted file. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-9501 http://www.cvedetails.com/cve/CVE-2017-9501/ https://github.com/ImageMagick/ImageMagick/commit/01843366d6a7b96e22ad7bb67f3df7d9fd4d5d74 https://github.com/ImageMagick/ImageMagick/issues/491
I do not get any assertion failure nor valgrind error with the testcase everywhere.
(I get various error messages though.)
Packages submitted in case someone would like to continue with the rest of bugs during my vacation.
SUSE-SU-2017:2176-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1042826,1043289,1049072 CVE References: CVE-2017-11403,CVE-2017-9439,CVE-2017-9501 Sources used: SUSE Linux Enterprise Software Development Kit 11-SP4 (src): ImageMagick-6.4.3.6-7.78.5.2 SUSE Linux Enterprise Server 11-SP4 (src): ImageMagick-6.4.3.6-7.78.5.2 SUSE Linux Enterprise Debuginfo 11-SP4 (src): ImageMagick-6.4.3.6-7.78.5.2
SUSE-SU-2017:2199-1: An update that fixes four vulnerabilities is now available. Category: security (important) Bug References: 1042812,1042826,1043289,1049072 CVE References: CVE-2017-11403,CVE-2017-9439,CVE-2017-9440,CVE-2017-9501 Sources used: SUSE Linux Enterprise Workstation Extension 12-SP3 (src): ImageMagick-6.8.8.1-71.5.3 SUSE Linux Enterprise Workstation Extension 12-SP2 (src): ImageMagick-6.8.8.1-71.5.3 SUSE Linux Enterprise Software Development Kit 12-SP3 (src): ImageMagick-6.8.8.1-71.5.3 SUSE Linux Enterprise Software Development Kit 12-SP2 (src): ImageMagick-6.8.8.1-71.5.3 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src): ImageMagick-6.8.8.1-71.5.3 SUSE Linux Enterprise Server 12-SP3 (src): ImageMagick-6.8.8.1-71.5.3 SUSE Linux Enterprise Server 12-SP2 (src): ImageMagick-6.8.8.1-71.5.3 SUSE Linux Enterprise Desktop 12-SP3 (src): ImageMagick-6.8.8.1-71.5.3 SUSE Linux Enterprise Desktop 12-SP2 (src): ImageMagick-6.8.8.1-71.5.3
SUSE-SU-2017:2229-1: An update that fixes 6 vulnerabilities is now available. Category: security (important) Bug References: 1036985,1042826,1043289,1049072,1050611,1050674 CVE References: CVE-2017-11403,CVE-2017-11636,CVE-2017-11643,CVE-2017-8350,CVE-2017-9439,CVE-2017-9501 Sources used: SUSE Studio Onsite 1.3 (src): GraphicsMagick-1.2.5-4.78.9.1 SUSE Linux Enterprise Software Development Kit 11-SP4 (src): GraphicsMagick-1.2.5-4.78.9.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): GraphicsMagick-1.2.5-4.78.9.1
released
openSUSE-SU-2017:2271-1: An update that fixes four vulnerabilities is now available. Category: security (important) Bug References: 1042812,1042826,1043289,1049072 CVE References: CVE-2017-11403,CVE-2017-9439,CVE-2017-9440,CVE-2017-9501 Sources used: openSUSE Leap 42.3 (src): ImageMagick-6.8.8.1-34.1 openSUSE Leap 42.2 (src): ImageMagick-6.8.8.1-30.6.1