SUSE update for ImageMagick



Published: 2023-12-03
Risk High
Patch available YES
Number of vulnerabilities 25
CVE-ID CVE-2019-17540
CVE-2020-21679
CVE-2021-20176
CVE-2021-20224
CVE-2021-20241
CVE-2021-20243
CVE-2021-20244
CVE-2021-20246
CVE-2021-20309
CVE-2021-20311
CVE-2021-20312
CVE-2021-20313
CVE-2022-0284
CVE-2022-2719
CVE-2022-28463
CVE-2022-32545
CVE-2022-32546
CVE-2022-32547
CVE-2022-44267
CVE-2022-44268
CVE-2023-1289
CVE-2023-34151
CVE-2023-3745
CVE-2023-5341
CVE-2021-3574
CWE-ID CWE-122
CWE-787
CWE-369
CWE-190
CWE-200
CWE-617
CWE-119
CWE-704
CWE-399
CWE-20
CWE-416
CWE-401
Exploitation vector Network
Public exploit Public exploit code for vulnerability #19 is available.
Public exploit code for vulnerability #20 is available.
Vulnerable software
Subscribe
SUSE Linux Enterprise Server for SAP Applications 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Server 15 SP1 LTSS
Operating systems & Components / Operating system

SUSE Linux Enterprise Server 15
Operating systems & Components / Operating system

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
Operating systems & Components / Operating system

SUSE Linux Enterprise High Performance Computing 15
Operating systems & Components / Operating system

SUSE CaaS Platform
Operating systems & Components / Operating system

ImageMagick-debuginfo
Operating systems & Components / Operating system package or component

ImageMagick-devel
Operating systems & Components / Operating system package or component

libMagickCore-7_Q16HDRI6
Operating systems & Components / Operating system package or component

ImageMagick-debugsource
Operating systems & Components / Operating system package or component

libMagick++-7_Q16HDRI4-debuginfo
Operating systems & Components / Operating system package or component

ImageMagick-config-7-upstream
Operating systems & Components / Operating system package or component

perl-PerlMagick
Operating systems & Components / Operating system package or component

perl-PerlMagick-debuginfo
Operating systems & Components / Operating system package or component

libMagickCore-7_Q16HDRI6-debuginfo
Operating systems & Components / Operating system package or component

libMagick++-7_Q16HDRI4
Operating systems & Components / Operating system package or component

libMagickWand-7_Q16HDRI6
Operating systems & Components / Operating system package or component

libMagick++-devel
Operating systems & Components / Operating system package or component

ImageMagick-config-7-SUSE
Operating systems & Components / Operating system package or component

ImageMagick
Operating systems & Components / Operating system package or component

libMagickWand-7_Q16HDRI6-debuginfo
Operating systems & Components / Operating system package or component

Vendor SUSE

Security Bulletin

This security bulletin contains information about 25 vulnerabilities.

1) Heap-based buffer overflow

EUVDB-ID: #VU30724

Risk: Medium

CVSSv3.1: 6.1 [CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-17540

CWE-ID: CWE-122 - Heap-based Buffer Overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the ReadPSInfo in coders/ps.c. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Out-of-bounds write

EUVDB-ID: #VU83626

Risk: High

CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2020-21679

CWE-ID: CWE-787 - Out-of-bounds write

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input within the WritePCXImage() function in pcx.c. A remote attacker can pass a specially crafted file to the application, trigger an out-of-bounds write and execute arbitrary code on the target system.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Division by zero

EUVDB-ID: #VU61578

Risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-20176

CWE-ID: CWE-369 - Divide By Zero

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a division by zero error within the gem.c file in ImageMagick. A remote attacker can pass specially crafted data to the application and crash it.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Integer overflow

EUVDB-ID: #VU67130

Risk: High

CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-20224

CWE-ID: CWE-190 - Integer overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow within the ExportIndexQuantum() function in MagickCore/quantum-export.c. A remote attacker can pass specially crafted image data to the application, trigger an integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

5) Division by zero

EUVDB-ID: #VU61576

Risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-20241

CWE-ID: CWE-369 - Divide By Zero

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a division by zero error within the coders/jp2.c file in ImageMagick. A remote attacker can pass specially crafted data to the application and crash it.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

6) Division by zero

EUVDB-ID: #VU61577

Risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-20243

CWE-ID: CWE-369 - Divide By Zero

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a division by zero error within the MagickCore/resize.c file in ImageMagick. A remote attacker can pass specially crafted data to the application and crash it.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

7) Division by zero

EUVDB-ID: #VU62872

Risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-20244

CWE-ID: CWE-369 - Divide By Zero

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a division by zero error in MagickCore/visual-effects.c . A remote attacker can pass specially crafted data to the application and crash it.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

8) Division by zero

EUVDB-ID: #VU62890

Risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-20246

CWE-ID: CWE-369 - Divide By Zero

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a division by zero error in MagickCore/resample.c. A remote attacker can pass a specially crafted data to the application and crash it.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

9) Division by zero

EUVDB-ID: #VU62868

Risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-20309

CWE-ID: CWE-369 - Divide By Zero

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a division by zero error in the WaveImage() function in MagickCore/visual-effects.c . A remote attacker can pass specially crafted image file to the application and crash it.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

10) Division by zero

EUVDB-ID: #VU62869

Risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-20311

CWE-ID: CWE-369 - Divide By Zero

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a division by zero error in the sRGBTransformImage() function in MagickCore/colorspace.c . A remote attacker can pass specially crafted image file to the application and crash it.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

11) Integer overflow

EUVDB-ID: #VU62867

Risk: High

CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-20312

CWE-ID: CWE-190 - Integer overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the WriteTHUMBNAILImage() function in coders/thumbnail.c. A remote attacker can pass specially crafted data to the application, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

12) Information disclosure

EUVDB-ID: #VU62861

Risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-20313

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to potential cipher leak when calculating signatures in TransformSignature() function in MagickCore/signature.c. A remote attacker can gain unauthorized access to sensitive information on the system.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

13) Heap-based buffer overflow

EUVDB-ID: #VU68077

Risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-0284

CWE-ID: CWE-122 - Heap-based Buffer Overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error when parsing TIFF files within the GetPixelAlpha() function in pixel-accessor.h. A remote attacker can pass specially crafted TIFF file to the application, trigger a heap-based buffer overflow and perform a denial of service (DoS) attack.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

14) Reachable Assertion

EUVDB-ID: #VU66952

Risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-2719

CWE-ID: CWE-617 - Reachable Assertion

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a reachable assertion when a call to WriteImages is made in MagickWand/operation.c because of a NULL image list. A remote attacker can pass specially crafted file to the affected application and perform a denial of service (DoS) attack.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

15) Buffer overflow

EUVDB-ID: #VU62851

Risk: High

CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-28463

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing Image files. A remote attacker can pass specially crafted data to the application, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

16) Integer overflow

EUVDB-ID: #VU64947

Risk: Low

CVSSv3.1: 3.8 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-32545

CWE-ID: CWE-190 - Integer overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service attack. 

The vulnerability exists due to integer overflow in coders/psd.c in the ImageMagick when processing crafted or untrusted input. A remote attacker can trick the victim into opening a specially crafted file and perform a denial of service attack. 

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

17) Integer overflow

EUVDB-ID: #VU64948

Risk: Low

CVSSv3.1: 3.8 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-32546

CWE-ID: CWE-190 - Integer overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to integer overflow in coders/pcl.c in the ImageMagick when processing crafted or untrusted input. A remote attacker can trick the victim into opening a specially crafted file and perform a denial of service attack.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

18) Type conversion

EUVDB-ID: #VU64949

Risk: Low

CVSSv3.1: 3.8 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-32547

CWE-ID: CWE-704 - Type conversion

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a load of misaligned address for type 'double' in MagickCore/property.c. A remote attacker can trick the victim into opening a specially crafted file and perform a denial of service attack.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

19) Resource management error

EUVDB-ID: #VU72079

Risk: Low

CVSSv3.1: 3.4 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C]

CVE-ID: CVE-2022-44267

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: Yes

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources when performing operations on crafted PNG images. A remote attacker can pass specially crafted PNG image to the application and force the application to wait indefinitely for the stdin input, consuming system resources.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.

20) Information disclosure

EUVDB-ID: #VU72078

Risk: Medium

CVSSv3.1: 5.9 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C]

CVE-ID: CVE-2022-44268

CWE-ID: CWE-200 - Information exposure

Exploit availability: Yes

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to improper input validation when performing operations (e.g. resizing) on specially crafted PNG images. A remote attacker can pass a specially crafted image to the application and embed contents of other files on the system into the resulting image.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.

21) Resource management error

EUVDB-ID: #VU74300

Risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-1289

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the application when parsing SVG files. A remote attacker can pass a specially crafted SVG file that contains many render actions and consume all available disk space on the system.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

22) Input validation error

EUVDB-ID: #VU76763

Risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-34151

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted image to the application and perform a denial of service (DoS) attack.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

23) Heap-based buffer overflow

EUVDB-ID: #VU78944

Risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-3745

CWE-ID: CWE-122 - Heap-based Buffer Overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error within the PushCharPixel() function in quantum-private.h. A remote attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and perform a denial of service (DoS) attack.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

24) Use-after-free

EUVDB-ID: #VU82972

Risk: High

CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-5341

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the ReadBMPImage() function in coders/bmp.c. A remote attacker can pass a specially crafted image to the application, trigger a use-after-free error and execute arbitrary code on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

25) Memory leak

EUVDB-ID: #VU68074

Risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-3574

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak when executing a crafted file with the convert command. A remote attacker can force the application to leak memory and perform denial of service attack.

Mitigation

Update the affected package ImageMagick to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise Server 15: SP1

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15: SP1

SUSE CaaS Platform: 4.0

ImageMagick-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-devel: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

ImageMagick-debugsource: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4-debuginfo: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-upstream: before 7.0.7.34-150000.3.123.1

perl-PerlMagick: before 7.0.7.34-150000.3.123.1

perl-PerlMagick-debuginfo: before 7.0.7.34-150000.3.123.1

libMagickCore-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

libMagick++-7_Q16HDRI4: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6: before 7.0.7.34-150000.3.123.1

libMagick++-devel: before 7.0.7.34-150000.3.123.1

ImageMagick-config-7-SUSE: before 7.0.7.34-150000.3.123.1

ImageMagick: before 7.0.7.34-150000.3.123.1

libMagickWand-7_Q16HDRI6-debuginfo: before 7.0.7.34-150000.3.123.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234634-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###