Bug 991444 (CVE-2016-5010) - VUL-1: CVE-2016-5010: ImageMagick: Out-of-bounds read when processing crafted tiff file
Summary: VUL-1: CVE-2016-5010: ImageMagick: Out-of-bounds read when processing crafted...
Status: RESOLVED FIXED
Alias: CVE-2016-5010
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/171475/
Whiteboard: CVSSv2:SUSE:CVE-2016-5010:4.3:(AV:N/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-08-01 09:52 UTC by Sebastian Krahmer
Modified: 2020-06-13 21:06 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sebastian Krahmer 2016-08-01 09:52:27 UTC
Quoting from RH BZ:

An out-of-bounds heap read vulnerability in ImageMagick compiled with TIFF support that can be triggered by running mogrify on crafted TIFF file was found.

rh#1354500



References:
https://bugzilla.redhat.com/show_bug.cgi?id=1354500
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-5010
Comment 3 Petr Gajdos 2016-08-04 13:10:22 UTC
11/ImageMagick seems not to not be affected.
Comment 4 Petr Gajdos 2016-08-04 18:49:41 UTC
GraphicsMagick seems not to be affected.
Comment 5 Petr Gajdos 2016-08-04 19:03:22 UTC
I believe all affected code streams are fixed.
Comment 6 Bernhard Wiedemann 2016-08-04 20:00:32 UTC
This is an autogenerated message for OBS integration:
This bug (991444) was mentioned in
https://build.opensuse.org/request/show/416993 13.2 / ImageMagick
Comment 8 Sebastian Krahmer 2016-08-15 11:49:20 UTC
released
Comment 9 Swamp Workflow Management 2016-08-15 13:10:39 UTC
openSUSE-SU-2016:2072-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 991444,991445,991872
CVE References: CVE-2016-5010,CVE-2016-6491,CVE-2016-6520
Sources used:
openSUSE 13.2 (src):    ImageMagick-6.8.9.8-29.1
Comment 10 Swamp Workflow Management 2016-08-15 15:09:42 UTC
SUSE-SU-2016:2076-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 991444,991445,991872
CVE References: CVE-2016-5010,CVE-2016-6491,CVE-2016-6520
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP1 (src):    ImageMagick-6.8.8.1-33.1
SUSE Linux Enterprise Software Development Kit 12-SP1 (src):    ImageMagick-6.8.8.1-33.1
SUSE Linux Enterprise Server 12-SP1 (src):    ImageMagick-6.8.8.1-33.1
SUSE Linux Enterprise Desktop 12-SP1 (src):    ImageMagick-6.8.8.1-33.1
Comment 11 Swamp Workflow Management 2016-08-24 16:09:31 UTC
openSUSE-SU-2016:2148-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 991444,991445,991872
CVE References: CVE-2016-5010,CVE-2016-6491,CVE-2016-6520
Sources used:
openSUSE Leap 42.1 (src):    ImageMagick-6.8.8.1-18.2