MGASA-2017-0297

Source
https://advisories.mageia.org/MGASA-2017-0297.html
Import Source
https://advisories.mageia.org/MGASA-2017-0297.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2017-0297
Related
Published
2017-08-23T15:43:04Z
Modified
2017-08-23T15:22:40Z
Summary
Updated graphicsmagick packages fix security vulnerability
Details

Invalid memory read in SetImageColorCallBack() in image.c (CVE-2017-12935).

Use-after-free in ReadWMFImage() in wmf.c (CVE-2017-12936).

Heap-based buffer overflow in ReadSUNImage() in sun.c (CVE-2017-12937).

References
Credits

Affected packages

Mageia:6 / graphicsmagick

Package

Name
graphicsmagick
Purl
pkg:rpm/mageia/graphicsmagick?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.26-1.3.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / graphicsmagick

Package

Name
graphicsmagick
Purl
pkg:rpm/mageia/graphicsmagick?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.26-1.2.mga5

Ecosystem specific

{
    "section": "core"
}