Bug 1178067 - (CVE-2020-27560) VUL-1: CVE-2020-27560: ImageMagick: division by zero in OptimizeLayerFrames function in MagickCore/layer.c
(CVE-2020-27560)
VUL-1: CVE-2020-27560: ImageMagick: division by zero in OptimizeLayerFrames f...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/270084/
CVSSv3.1:SUSE:CVE-2020-27560:4.3:(AV:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-10-23 12:20 UTC by Alexandros Toptsoglou
Modified: 2020-11-15 11:14 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Alexandros Toptsoglou 2020-10-23 12:31:44 UTC
Tracked SLE11, SLE12, SLE15 and SLE15-SP2 as affected. I could not find a POC in the upstream bug.
Comment 2 Petr Gajdos 2020-10-26 11:22:08 UTC
TW: will be fixed in 7.0.10-35, not available yet.

ImageMagick6 commit
https://github.com/ImageMagick/ImageMagick6/commit/6e3b13c7ef94d72b40fba91987897c4326717a46

Submitted for 15sp2/ImageMagick, 15/ImageMagick, 12/ImageMagick and 11/ImageMagick.

I believe all fixed.
Comment 4 Swamp Workflow Management 2020-11-05 14:17:16 UTC
SUSE-SU-2020:3162-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1178067
CVE References: CVE-2020-27560
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for Development Tools 15-SP1 (src):    ImageMagick-7.0.7.34-3.85.1
SUSE Linux Enterprise Module for Desktop Applications 15-SP1 (src):    ImageMagick-7.0.7.34-3.85.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 5 Swamp Workflow Management 2020-11-05 14:18:23 UTC
SUSE-SU-2020:3164-1: An update that solves one vulnerability and has one errata is now available.

Category: security (moderate)
Bug References: 1106272,1178067
CVE References: CVE-2020-27560
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for Development Tools 15-SP2 (src):    ImageMagick-7.0.7.34-10.3.1
SUSE Linux Enterprise Module for Desktop Applications 15-SP2 (src):    ImageMagick-7.0.7.34-10.3.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 Swamp Workflow Management 2020-11-05 14:23:13 UTC
SUSE-SU-2020:3163-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1178067
CVE References: CVE-2020-27560
JIRA References: 
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP5 (src):    ImageMagick-6.8.8.1-71.147.1
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    ImageMagick-6.8.8.1-71.147.1
SUSE Linux Enterprise Server 12-SP5 (src):    ImageMagick-6.8.8.1-71.147.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Swamp Workflow Management 2020-11-09 17:19:17 UTC
openSUSE-SU-2020:1884-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1178067
CVE References: CVE-2020-27560
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    ImageMagick-7.0.7.34-lp152.12.6.1
Comment 8 Marcus Meissner 2020-11-12 16:29:01 UTC
done
Comment 9 Swamp Workflow Management 2020-11-15 11:14:25 UTC
openSUSE-SU-2020:1927-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1178067
CVE References: CVE-2020-27560
JIRA References: 
Sources used:
openSUSE Leap 15.1 (src):    ImageMagick-7.0.7.34-lp151.7.22.1