Upstream information
Description
Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow. NOTE: some of these details are obtained from third party information.NVD CVSS v2 Base Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Novell/SUSE information
Novell Bugzilla entry: 507728 SUSE Security Advisories:- SUSE-SR:2009:012, published Fri, 03 Jul 2009 16:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| Novell Linux Desktop 9 for x86 Novell Linux Desktop 9 for x86_64 |
| core9.x86-64 core9.ia64 sles9-nld.x86-64 core9.s390 core9.s390x sles9-nld.x86 core9.ppc core9.x86 YOU Patch Nr: 12437 |
| SLES SDK 9 for IBM S/390 and IBM zSeries SLES SDK 9 for IBM iSeries and IBM pSeries SLES SDK 9 for IBM zSeries SLES SDK 9 for IPF SLES SDK 9 for X86-64 SLES SDK 9 for x86 |
| core9.x86-64 core9.ia64 sles9-nld.x86-64 core9.s390 core9.s390x sles9-nld.x86 core9.ppc core9.x86 YOU Patch Nr: 12437 |
| openSUSE 10.3 |
| |
| openSUSE 10.3 |
| |
| SUSE Linux Enterprise Desktop 10 SP2 for AMD64 and Intel EM64T SUSE Linux Enterprise Desktop 10 SP2 for x86 |
| sled10-sp2.x86-64 sle10-sp2-sdk.ia64 sle10-sp2-sdk.ppc sled10-sp2.x86 sle10-sp2-sdk.s390x sle10-sp2-sdk.x86 sle10-sp2-sdk.x86-64 ZYPP Patch Nr: 6284 |
