MGASA-2016-0252

Source
https://advisories.mageia.org/MGASA-2016-0252.html
Import Source
https://advisories.mageia.org/MGASA-2016-0252.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2016-0252
Related
Published
2016-07-14T20:33:59Z
Modified
2016-07-14T20:26:22Z
Summary
Updated graphicsmagick packages fix security vulnerability
Details
  • A read out-of-bound in the parsing of gif files using GraphicsMagick (CVE-2015-8808).

  • Infinite loop caused by converting a circularly defined svg file (CVE-2016-5240).

  • Fix another case of CVE-2016-2317 (heap buffer overflow) in the MVG rendering code (also impacts SVG).

  • arithmetic exception converting a svg file (CVE-2016-5241)

  • Arithmetic exception converting a svg file caused by a X%0 operation in magick/render.c (CVE-2016-2318)

  • A shell exploit (CVE-2016-5118) was discovered associated with a filename syntax where file names starting with '|' are intepreted as shell commands executed via popen(). Insufficient sanitization in the SVG and MVG renderers allows such filenames to be passed through from potentially untrusted files. There might be other ways for untrusted inputs to produce such filenames. Due to this issue, support for the feature is removed entirely.

The gnudl, octave, pdf2djvu, and photoqt packages have been rebuilt to use the updated GraphicsMagick++ library.

References
Credits

Affected packages

Mageia:5 / graphicsmagick

Package

Name
graphicsmagick
Purl
pkg:rpm/mageia/graphicsmagick?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.24-1.2.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / gnudl

Package

Name
gnudl
Purl
pkg:rpm/mageia/gnudl?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.5-2.1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / octave

Package

Name
octave
Purl
pkg:rpm/mageia/octave?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.8.2-3.1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / pdf2djvu

Package

Name
pdf2djvu
Purl
pkg:rpm/mageia/pdf2djvu?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.7.17-4.1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / photoqt

Package

Name
photoqt
Purl
pkg:rpm/mageia/photoqt?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0-4.1.mga5

Ecosystem specific

{
    "section": "core"
}