Bug 903204 (CVE-2014-8354) - VUL-1: CVE-2014-8354: ImageMagick: out-of-bounds memory access in resize code
Summary: VUL-1: CVE-2014-8354: ImageMagick: out-of-bounds memory access in resize code
Status: RESOLVED FIXED
Alias: CVE-2014-8354
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Minor
Target Milestone: ---
Deadline: 2014-11-27
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/110235/
Whiteboard: maint:released:sle11-sp1:59862 maint:...
Keywords:
Depends on:
Blocks:
 
Reported: 2014-10-30 10:13 UTC by Victor Pereira
Modified: 2014-12-15 10:15 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2014-10-30 10:13:52 UTC
CVE-2014-8354

ImageMagick 6.8.9-9 fixes an unspecified bug in image resize code.Upstream released version 6.8.9-9 which fixes it.

probably minor issue with low severity.


References:
https://bugs.gentoo.org/show_bug.cgi?id=527028
https://bugzilla.redhat.com/show_bug.cgi?id=1158518
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-8354
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8354
Comment 1 Petr Gajdos 2014-10-30 13:04:20 UTC
Fixed for factory.
Comment 3 Petr Gajdos 2014-11-04 07:29:34 UTC
Hmm, redhat bug reffers to
http://trac.imagemagick.org/changeset/16436#file0
Comment 4 Petr Gajdos 2014-11-04 07:33:29 UTC
I need more informations what actually has to be fixed than 'an unspecified bug in image resize code'.
Comment 7 Petr Gajdos 2014-11-04 12:12:53 UTC
All packages are submitted I believe.
Comment 10 Swamp Workflow Management 2014-11-12 10:04:56 UTC
openSUSE-SU-2014:1396-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 903204,903216,903638
CVE References: CVE-2014-8354,CVE-2014-8355,CVE-2014-8562
Sources used:
openSUSE 13.2 (src):    ImageMagick-6.8.9.8-4.1
openSUSE 13.1 (src):    ImageMagick-6.8.6.9-2.24.1
openSUSE 12.3 (src):    ImageMagick-6.7.8.8-4.17.1
Comment 11 Swamp Workflow Management 2014-11-13 11:35:21 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2014-11-27.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/59636
Comment 13 Petr Gajdos 2014-11-13 16:02:37 UTC
openSUSE: mr#261433
sle12:    mr#46276
11:       sr#46277
10sp3:    sr#46279
Comment 15 Petr Gajdos 2014-11-14 11:40:03 UTC
.
Comment 17 Swamp Workflow Management 2014-12-08 16:07:20 UTC
SUSE-SU-2014:1595-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 903204,903216,903638,905260
CVE References: CVE-2014-8354,CVE-2014-8355,CVE-2014-8562,CVE-2014-8716
Sources used:
SUSE Linux Enterprise Workstation Extension 12 (src):    ImageMagick-6.8.8.1-8.2
SUSE Linux Enterprise Software Development Kit 12 (src):    ImageMagick-6.8.8.1-8.2
SUSE Linux Enterprise Server 12 (src):    ImageMagick-6.8.8.1-8.2
SUSE Linux Enterprise Desktop 12 (src):    ImageMagick-6.8.8.1-8.2
Comment 18 Swamp Workflow Management 2014-12-13 05:04:53 UTC
SUSE-SU-2014:1631-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 903204,903216,903638,905260
CVE References: CVE-2014-8354,CVE-2014-8355,CVE-2014-8562,CVE-2014-8716
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    ImageMagick-6.4.3.6-7.30.1
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    ImageMagick-6.4.3.6-7.30.1
SUSE Linux Enterprise Server 11 SP3 (src):    ImageMagick-6.4.3.6-7.30.1
SUSE Linux Enterprise Desktop 11 SP3 (src):    ImageMagick-6.4.3.6-7.30.1
Comment 19 Marcus Meissner 2014-12-15 10:13:33 UTC
rekleased