{"schema_version":"1.7.3","id":"SUSE-SU-2019:2896-1","published":"2019-11-05T10:44:40Z","modified":"2026-02-04T03:19:44.700983Z","related":["CVE-2019-14980","CVE-2019-14981","CVE-2019-15139","CVE-2019-15140","CVE-2019-15141","CVE-2019-16708","CVE-2019-16709","CVE-2019-16710","CVE-2019-16711","CVE-2019-16712","CVE-2019-16713"],"upstream":["CVE-2019-14980","CVE-2019-14981","CVE-2019-15139","CVE-2019-15140","CVE-2019-15141","CVE-2019-16708","CVE-2019-16709","CVE-2019-16710","CVE-2019-16711","CVE-2019-16712","CVE-2019-16713"],"summary":"Security update for ImageMagick","details":"This update for ImageMagick fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2019-15139: Fixed a denial-of-service vulnerability in ReadXWDImage (bsc#1146213).\n- CVE-2019-15140: Fixed a use-after-free bug in the Matlab image parser (bsc#1146212).\n- CVE-2019-15141: Fixed a divide-by-zero vulnerability in the MeanShiftImage function (bsc#1146211).\n- CVE-2019-14980: Fixed an application crash resulting from a heap-based buffer over-read in WriteTIFFImage (bsc#1146068).\n- CVE-2019-14981: Fixed a use after free in the UnmapBlob function (bsc#1146065).\n- CVE-2019-16708: Fixed a memory leak in magick/xwindow.c (bsc#1151781).\n- CVE-2019-16709: Fixed a memory leak in coders/dps.c (bsc#1151782).\n- CVE-2019-16710: Fixed a memory leak in coders/dot.c (bsc#1151783).\n- CVE-2019-16711: Fixed a memory leak in Huffman2DEncodeImage in coders/ps2.c (bsc#1151784).\n- CVE-2019-16712: Fixed a memory leak in Huffman2DEncodeImage in coders/ps3.c (bsc#1151785).\n- CVE-2019-16713: Fixed a memory leak in coders/dot.c (bsc#1151786).\n","affected":[{"package":{"name":"ImageMagick","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15","purl":"pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.7.34-3.72.1"}]}],"ecosystem_specific":{"binaries":[{"ImageMagick":"7.0.7.34-3.72.1","ImageMagick-config-7-SUSE":"7.0.7.34-3.72.1","ImageMagick-config-7-upstream":"7.0.7.34-3.72.1","ImageMagick-devel":"7.0.7.34-3.72.1","libMagick++-7_Q16HDRI4":"7.0.7.34-3.72.1","libMagick++-devel":"7.0.7.34-3.72.1","libMagickCore-7_Q16HDRI6":"7.0.7.34-3.72.1","libMagickWand-7_Q16HDRI6":"7.0.7.34-3.72.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2896-1.json"}},{"package":{"name":"ImageMagick","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15 SP1","purl":"pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.7.34-3.72.1"}]}],"ecosystem_specific":{"binaries":[{"ImageMagick":"7.0.7.34-3.72.1","ImageMagick-config-7-SUSE":"7.0.7.34-3.72.1","ImageMagick-devel":"7.0.7.34-3.72.1","libMagick++-7_Q16HDRI4":"7.0.7.34-3.72.1","libMagick++-devel":"7.0.7.34-3.72.1","libMagickCore-7_Q16HDRI6":"7.0.7.34-3.72.1","libMagickWand-7_Q16HDRI6":"7.0.7.34-3.72.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2896-1.json"}},{"package":{"name":"ImageMagick","ecosystem":"SUSE:Linux Enterprise Module for Development Tools 15","purl":"pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.7.34-3.72.1"}]}],"ecosystem_specific":{"binaries":[{"perl-PerlMagick":"7.0.7.34-3.72.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2896-1.json"}},{"package":{"name":"ImageMagick","ecosystem":"SUSE:Linux Enterprise Module for Development Tools 15 SP1","purl":"pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.7.34-3.72.1"}]}],"ecosystem_specific":{"binaries":[{"perl-PerlMagick":"7.0.7.34-3.72.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2896-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2019/suse-su-20192896-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1146065"},{"type":"REPORT","url":"https://bugzilla.suse.com/1146068"},{"type":"REPORT","url":"https://bugzilla.suse.com/1146211"},{"type":"REPORT","url":"https://bugzilla.suse.com/1146212"},{"type":"REPORT","url":"https://bugzilla.suse.com/1146213"},{"type":"REPORT","url":"https://bugzilla.suse.com/1151781"},{"type":"REPORT","url":"https://bugzilla.suse.com/1151782"},{"type":"REPORT","url":"https://bugzilla.suse.com/1151783"},{"type":"REPORT","url":"https://bugzilla.suse.com/1151784"},{"type":"REPORT","url":"https://bugzilla.suse.com/1151785"},{"type":"REPORT","url":"https://bugzilla.suse.com/1151786"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-14980"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-14981"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-15139"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-15140"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-15141"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-16708"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-16709"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-16710"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-16711"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-16712"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-16713"}]}