Bug 991872 (CVE-2016-6520) - VUL-0: CVE-2016-6520: ImageMagick buffer overflow
Summary: VUL-0: CVE-2016-6520: ImageMagick buffer overflow
Status: RESOLVED FIXED
Alias: CVE-2016-6520
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/171569/
Whiteboard: CVSSv2:RedHat:CVE-2016-6520:4.3:(AV:N...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-08-03 08:53 UTC by Sebastian Krahmer
Modified: 2016-08-24 16:09 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sebastian Krahmer 2016-08-03 08:53:08 UTC
Quoting from OSS-sec:

Hi CVE assignemnt team,
I would like to request a CVE for a buffer overflow that was found in
ImageMagick. You can find the fix in the following commit:
https://github.com/ImageMagick/ImageMagick/commit/76401e172ea3a55182be2b8e2aca4d07270f6da6


CVE-2016-6520



References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-6520
http://seclists.org/oss-sec/2016/q3/230
Comment 2 Petr Gajdos 2016-08-04 18:49:50 UTC
GraphicsMagick seems not to be affected.
Comment 3 Petr Gajdos 2016-08-04 19:03:03 UTC
I believe all affected code streams are fixed.
Comment 4 Bernhard Wiedemann 2016-08-04 20:00:55 UTC
This is an autogenerated message for OBS integration:
This bug (991872) was mentioned in
https://build.opensuse.org/request/show/416993 13.2 / ImageMagick
Comment 6 Sebastian Krahmer 2016-08-15 11:47:47 UTC
released
Comment 7 Swamp Workflow Management 2016-08-15 13:10:58 UTC
openSUSE-SU-2016:2072-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 991444,991445,991872
CVE References: CVE-2016-5010,CVE-2016-6491,CVE-2016-6520
Sources used:
openSUSE 13.2 (src):    ImageMagick-6.8.9.8-29.1
Comment 8 Swamp Workflow Management 2016-08-15 15:09:19 UTC
SUSE-SU-2016:2075-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 991445,991872
CVE References: CVE-2016-6491,CVE-2016-6520
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    ImageMagick-6.4.3.6-7.48.1
SUSE Linux Enterprise Server 11-SP4 (src):    ImageMagick-6.4.3.6-7.48.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    ImageMagick-6.4.3.6-7.48.1
Comment 9 Swamp Workflow Management 2016-08-15 15:10:01 UTC
SUSE-SU-2016:2076-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 991444,991445,991872
CVE References: CVE-2016-5010,CVE-2016-6491,CVE-2016-6520
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP1 (src):    ImageMagick-6.8.8.1-33.1
SUSE Linux Enterprise Software Development Kit 12-SP1 (src):    ImageMagick-6.8.8.1-33.1
SUSE Linux Enterprise Server 12-SP1 (src):    ImageMagick-6.8.8.1-33.1
SUSE Linux Enterprise Desktop 12-SP1 (src):    ImageMagick-6.8.8.1-33.1
Comment 10 Swamp Workflow Management 2016-08-24 16:09:48 UTC
openSUSE-SU-2016:2148-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 991444,991445,991872
CVE References: CVE-2016-5010,CVE-2016-6491,CVE-2016-6520
Sources used:
openSUSE Leap 42.1 (src):    ImageMagick-6.8.8.1-18.2