Mageia 2023-0161: imagemagick security update
Summary
A heap-based buffer overflow issue was discovered in ImageMagick's
ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An
attacker could pass specially crafted file to convert, triggering an
out-of-bounds read error, allowing an application to crash, resulting in a
denial of service. (CVE-2023-1906)
References
- https://bugs.mageia.org/show_bug.cgi?id=31817
- https://lists.suse.com/pipermail/sle-security-updates/2023-April/014519.html
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-35q2-86c7-9247
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1906
Resolution
MGASA-2023-0161 - Updated imagemagick packages fix security vulnerability
SRPMS
- 8/core/imagemagick-7.1.0.62-1.1.mga8
- 8/tainted/imagemagick-7.1.0.62-1.1.mga8.tainted