Upstream information

CVE-2019-9956 at MITRE

Description

In ImageMagick 7.0.8-35 Q16, there is a stack-based buffer overflow in the function PopHexPixel of coders/ps.c, which allows an attacker to cause a denial of service or code execution via a crafted image file.

SUSE information

SUSE Bugzilla entry: 1130330 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Enterprise Storage 4
  • ImageMagick >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-SUSE >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-upstream >= 6.8.8.1-71.108.1
  • libMagickCore-6_Q16-1 >= 6.8.8.1-71.108.1
  • libMagickWand-6_Q16-1 >= 6.8.8.1-71.108.1
Patchnames:
SUSE-Storage-4-2019-1033
SUSE Linux Enterprise Desktop 12 SP3
  • ImageMagick >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-SUSE >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-upstream >= 6.8.8.1-71.108.1
  • libMagick++-6_Q16-3 >= 6.8.8.1-71.108.1
  • libMagickCore-6_Q16-1 >= 6.8.8.1-71.108.1
  • libMagickCore-6_Q16-1-32bit >= 6.8.8.1-71.108.1
  • libMagickWand-6_Q16-1 >= 6.8.8.1-71.108.1
Patchnames:
SUSE-SLE-DESKTOP-12-SP3-2019-1033
SUSE Linux Enterprise Desktop 12 SP4
  • ImageMagick >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-SUSE >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-upstream >= 6.8.8.1-71.108.1
  • libMagick++-6_Q16-3 >= 6.8.8.1-71.108.1
  • libMagickCore-6_Q16-1 >= 6.8.8.1-71.108.1
  • libMagickCore-6_Q16-1-32bit >= 6.8.8.1-71.108.1
  • libMagickWand-6_Q16-1 >= 6.8.8.1-71.108.1
Patchnames:
SUSE-SLE-DESKTOP-12-SP4-2019-1033
SUSE Linux Enterprise High Performance Computing 12 SP5
SUSE Linux Enterprise Server 12 SP5
  • ImageMagick-config-6-SUSE >= 6.8.8.1-71.126.1
  • ImageMagick-config-6-upstream >= 6.8.8.1-71.126.1
  • libMagickCore-6_Q16-1 >= 6.8.8.1-71.126.1
  • libMagickWand-6_Q16-1 >= 6.8.8.1-71.126.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP1
  • ImageMagick >= 7.0.7.34-3.54.3
  • ImageMagick-config-7-SUSE >= 7.0.7.34-3.54.3
  • ImageMagick-devel >= 7.0.7.34-3.54.3
  • libMagick++-7_Q16HDRI4 >= 7.0.7.34-3.54.3
  • libMagick++-devel >= 7.0.7.34-3.54.3
  • libMagickCore-7_Q16HDRI6 >= 7.0.7.34-3.54.3
  • libMagickWand-7_Q16HDRI6 >= 7.0.7.34-3.54.3
SUSE Linux Enterprise Module for Desktop Applications 15
  • ImageMagick >= 7.0.7.34-3.54.3
  • ImageMagick-config-7-SUSE >= 7.0.7.34-3.54.3
  • ImageMagick-config-7-upstream >= 7.0.7.34-3.54.3
  • ImageMagick-devel >= 7.0.7.34-3.54.3
  • libMagick++-7_Q16HDRI4 >= 7.0.7.34-3.54.3
  • libMagick++-devel >= 7.0.7.34-3.54.3
  • libMagickCore-7_Q16HDRI6 >= 7.0.7.34-3.54.3
  • libMagickWand-7_Q16HDRI6 >= 7.0.7.34-3.54.3
Patchnames:
SUSE-SLE-Module-Desktop-Applications-15-2019-1019
SUSE Linux Enterprise Module for Development Tools 15 SP1
  • perl-PerlMagick >= 7.0.7.34-3.54.3
SUSE Linux Enterprise Module for Development Tools 15
  • ImageMagick >= 7.0.7.34-3.54.3
  • perl-PerlMagick >= 7.0.7.34-3.54.3
Patchnames:
SUSE-SLE-Module-Development-Tools-15-2019-1019
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15
  • ImageMagick >= 7.0.7.34-3.54.3
  • ImageMagick-doc >= 7.0.7.34-3.54.3
  • ImageMagick-extra >= 7.0.7.34-3.54.3
Patchnames:
SUSE-SLE-Module-Development-Tools-OBS-15-2019-1019
SUSE Linux Enterprise Point of Sale 12 SP2-CLIENT
  • ImageMagick >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-SUSE >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-upstream >= 6.8.8.1-71.108.1
  • libMagickCore-6_Q16-1 >= 6.8.8.1-71.108.1
  • libMagickWand-6_Q16-1 >= 6.8.8.1-71.108.1
Patchnames:
SUSE-SLE-POS-12-SP2-CLIENT-2019-1033
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server for SAP Applications 12 SP1-LTSS
  • ImageMagick >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-SUSE >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-upstream >= 6.8.8.1-71.108.1
  • libMagickCore-6_Q16-1 >= 6.8.8.1-71.108.1
  • libMagickWand-6_Q16-1 >= 6.8.8.1-71.108.1
Patchnames:
SUSE-SLE-SERVER-12-SP1-2019-1033
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server for SAP Applications 12 SP2-BCL
  • ImageMagick >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-SUSE >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-upstream >= 6.8.8.1-71.108.1
  • libMagickCore-6_Q16-1 >= 6.8.8.1-71.108.1
  • libMagickWand-6_Q16-1 >= 6.8.8.1-71.108.1
Patchnames:
SUSE-SLE-SERVER-12-SP2-BCL-2019-1033
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server for SAP Applications 12 SP2-ESPOS
  • ImageMagick >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-SUSE >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-upstream >= 6.8.8.1-71.108.1
  • libMagickCore-6_Q16-1 >= 6.8.8.1-71.108.1
  • libMagickWand-6_Q16-1 >= 6.8.8.1-71.108.1
Patchnames:
SUSE-SLE-SERVER-12-SP2-ESPOS-2019-1033
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server for SAP Applications 12 SP2-LTSS
  • ImageMagick >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-SUSE >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-upstream >= 6.8.8.1-71.108.1
  • libMagickCore-6_Q16-1 >= 6.8.8.1-71.108.1
  • libMagickWand-6_Q16-1 >= 6.8.8.1-71.108.1
Patchnames:
SUSE-SLE-SERVER-12-SP2-2019-1033
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server for SAP Applications 12 SP3
  • ImageMagick >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-SUSE >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-upstream >= 6.8.8.1-71.108.1
  • libMagickCore-6_Q16-1 >= 6.8.8.1-71.108.1
  • libMagickWand-6_Q16-1 >= 6.8.8.1-71.108.1
Patchnames:
SUSE-SLE-SERVER-12-SP3-2019-1033
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP4
  • ImageMagick >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-SUSE >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-upstream >= 6.8.8.1-71.108.1
  • libMagickCore-6_Q16-1 >= 6.8.8.1-71.108.1
  • libMagickWand-6_Q16-1 >= 6.8.8.1-71.108.1
Patchnames:
SUSE-SLE-SERVER-12-SP4-2019-1033
SUSE Linux Enterprise Server 12-LTSS
SUSE Linux Enterprise Server for SAP Applications 12-LTSS
  • ImageMagick >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-SUSE >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-upstream >= 6.8.8.1-71.108.1
  • libMagickCore-6_Q16-1 >= 6.8.8.1-71.108.1
  • libMagickWand-6_Q16-1 >= 6.8.8.1-71.108.1
Patchnames:
SUSE-SLE-SERVER-12-2019-1033
SUSE Linux Enterprise Server for SAP Applications 12 SP1
  • ImageMagick >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-SUSE >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-upstream >= 6.8.8.1-71.108.1
  • libMagickCore-6_Q16-1 >= 6.8.8.1-71.108.1
  • libMagickWand-6_Q16-1 >= 6.8.8.1-71.108.1
Patchnames:
SUSE-SLE-SAP-12-SP1-2019-1033
SUSE Linux Enterprise Server for SAP Applications 12 SP2
  • ImageMagick >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-SUSE >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-upstream >= 6.8.8.1-71.108.1
  • libMagickCore-6_Q16-1 >= 6.8.8.1-71.108.1
  • libMagickWand-6_Q16-1 >= 6.8.8.1-71.108.1
Patchnames:
SUSE-SLE-SAP-12-SP2-2019-1033
SUSE Linux Enterprise Software Development Kit 12 SP3
  • ImageMagick >= 6.8.8.1-71.108.1
  • ImageMagick-devel >= 6.8.8.1-71.108.1
  • libMagick++-6_Q16-3 >= 6.8.8.1-71.108.1
  • libMagick++-devel >= 6.8.8.1-71.108.1
  • perl-PerlMagick >= 6.8.8.1-71.108.1
Patchnames:
SUSE-SLE-SDK-12-SP3-2019-1033
SUSE Linux Enterprise Software Development Kit 12 SP4
  • ImageMagick >= 6.8.8.1-71.108.1
  • ImageMagick-devel >= 6.8.8.1-71.108.1
  • libMagick++-6_Q16-3 >= 6.8.8.1-71.108.1
  • libMagick++-devel >= 6.8.8.1-71.108.1
  • perl-PerlMagick >= 6.8.8.1-71.108.1
Patchnames:
SUSE-SLE-SDK-12-SP4-2019-1033
SUSE Linux Enterprise Software Development Kit 12 SP5
  • ImageMagick >= 6.8.8.1-71.126.1
  • ImageMagick-config-6-SUSE >= 6.8.8.1-71.126.1
  • ImageMagick-config-6-upstream >= 6.8.8.1-71.126.1
  • ImageMagick-devel >= 6.8.8.1-71.126.1
  • libMagick++-6_Q16-3 >= 6.8.8.1-71.126.1
  • libMagick++-devel >= 6.8.8.1-71.126.1
  • perl-PerlMagick >= 6.8.8.1-71.126.1
SUSE Linux Enterprise Workstation Extension 12 SP3
  • ImageMagick >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-SUSE >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-upstream >= 6.8.8.1-71.108.1
  • libMagick++-6_Q16-3 >= 6.8.8.1-71.108.1
  • libMagickCore-6_Q16-1-32bit >= 6.8.8.1-71.108.1
Patchnames:
SUSE-SLE-WE-12-SP3-2019-1033
SUSE Linux Enterprise Workstation Extension 12 SP4
  • ImageMagick >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-SUSE >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-upstream >= 6.8.8.1-71.108.1
  • libMagick++-6_Q16-3 >= 6.8.8.1-71.108.1
  • libMagickCore-6_Q16-1-32bit >= 6.8.8.1-71.108.1
Patchnames:
SUSE-SLE-WE-12-SP4-2019-1033
SUSE Linux Enterprise Workstation Extension 12 SP5
  • ImageMagick >= 6.8.8.1-71.126.1
  • libMagick++-6_Q16-3 >= 6.8.8.1-71.126.1
  • libMagickCore-6_Q16-1-32bit >= 6.8.8.1-71.126.1
SUSE OpenStack Cloud 7
  • ImageMagick >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-SUSE >= 6.8.8.1-71.108.1
  • ImageMagick-config-6-upstream >= 6.8.8.1-71.108.1
  • libMagickCore-6_Q16-1 >= 6.8.8.1-71.108.1
  • libMagickWand-6_Q16-1 >= 6.8.8.1-71.108.1
Patchnames:
SUSE-OpenStack-Cloud-7-2019-1033
openSUSE Leap 15.0
  • ImageMagick >= 7.0.7.34-lp150.2.29.1
  • ImageMagick-config-7-SUSE >= 7.0.7.34-lp150.2.29.1
  • ImageMagick-config-7-upstream >= 7.0.7.34-lp150.2.29.1
  • ImageMagick-debuginfo >= 7.0.7.34-lp150.2.29.1
  • ImageMagick-debugsource >= 7.0.7.34-lp150.2.29.1
  • ImageMagick-devel >= 7.0.7.34-lp150.2.29.1
  • ImageMagick-devel-32bit >= 7.0.7.34-lp150.2.29.1
  • ImageMagick-doc >= 7.0.7.34-lp150.2.29.1
  • ImageMagick-extra >= 7.0.7.34-lp150.2.29.1
  • ImageMagick-extra-debuginfo >= 7.0.7.34-lp150.2.29.1
  • libMagick++-7_Q16HDRI4 >= 7.0.7.34-lp150.2.29.1
  • libMagick++-7_Q16HDRI4-32bit >= 7.0.7.34-lp150.2.29.1
  • libMagick++-7_Q16HDRI4-32bit-debuginfo >= 7.0.7.34-lp150.2.29.1
  • libMagick++-7_Q16HDRI4-debuginfo >= 7.0.7.34-lp150.2.29.1
  • libMagick++-devel >= 7.0.7.34-lp150.2.29.1
  • libMagick++-devel-32bit >= 7.0.7.34-lp150.2.29.1
  • libMagickCore-7_Q16HDRI6 >= 7.0.7.34-lp150.2.29.1
  • libMagickCore-7_Q16HDRI6-32bit >= 7.0.7.34-lp150.2.29.1
  • libMagickCore-7_Q16HDRI6-32bit-debuginfo >= 7.0.7.34-lp150.2.29.1
  • libMagickCore-7_Q16HDRI6-debuginfo >= 7.0.7.34-lp150.2.29.1
  • libMagickWand-7_Q16HDRI6 >= 7.0.7.34-lp150.2.29.1
  • libMagickWand-7_Q16HDRI6-32bit >= 7.0.7.34-lp150.2.29.1
  • libMagickWand-7_Q16HDRI6-32bit-debuginfo >= 7.0.7.34-lp150.2.29.1
  • libMagickWand-7_Q16HDRI6-debuginfo >= 7.0.7.34-lp150.2.29.1
  • perl-PerlMagick >= 7.0.7.34-lp150.2.29.1
  • perl-PerlMagick-debuginfo >= 7.0.7.34-lp150.2.29.1
Patchnames:
openSUSE-2019-1331
openSUSE Leap 42.3
  • ImageMagick >= 6.8.8.1-82.1
  • ImageMagick-config-6-SUSE >= 6.8.8.1-82.1
  • ImageMagick-config-6-upstream >= 6.8.8.1-82.1
  • ImageMagick-debuginfo >= 6.8.8.1-82.1
  • ImageMagick-debugsource >= 6.8.8.1-82.1
  • ImageMagick-devel >= 6.8.8.1-82.1
  • ImageMagick-devel-32bit >= 6.8.8.1-82.1
  • ImageMagick-doc >= 6.8.8.1-82.1
  • ImageMagick-extra >= 6.8.8.1-82.1
  • ImageMagick-extra-debuginfo >= 6.8.8.1-82.1
  • libMagick++-6_Q16-3 >= 6.8.8.1-82.1
  • libMagick++-6_Q16-3-32bit >= 6.8.8.1-82.1
  • libMagick++-6_Q16-3-debuginfo >= 6.8.8.1-82.1
  • libMagick++-6_Q16-3-debuginfo-32bit >= 6.8.8.1-82.1
  • libMagick++-devel >= 6.8.8.1-82.1
  • libMagick++-devel-32bit >= 6.8.8.1-82.1
  • libMagickCore-6_Q16-1 >= 6.8.8.1-82.1
  • libMagickCore-6_Q16-1-32bit >= 6.8.8.1-82.1
  • libMagickCore-6_Q16-1-debuginfo >= 6.8.8.1-82.1
  • libMagickCore-6_Q16-1-debuginfo-32bit >= 6.8.8.1-82.1
  • libMagickWand-6_Q16-1 >= 6.8.8.1-82.1
  • libMagickWand-6_Q16-1-32bit >= 6.8.8.1-82.1
  • libMagickWand-6_Q16-1-debuginfo >= 6.8.8.1-82.1
  • libMagickWand-6_Q16-1-debuginfo-32bit >= 6.8.8.1-82.1
  • perl-PerlMagick >= 6.8.8.1-82.1
  • perl-PerlMagick-debuginfo >= 6.8.8.1-82.1
Patchnames:
openSUSE-2019-1320