{"schema_version":"1.7.3","id":"SUSE-SU-2021:14598-1","published":"2021-01-15T15:30:02Z","modified":"2026-02-04T04:07:00.584703Z","related":["CVE-2020-19667","CVE-2020-25664","CVE-2020-25666","CVE-2020-27751","CVE-2020-27752","CVE-2020-27753","CVE-2020-27754","CVE-2020-27755","CVE-2020-27759","CVE-2020-27760","CVE-2020-27761","CVE-2020-27763","CVE-2020-27765","CVE-2020-27767","CVE-2020-27768","CVE-2020-27769","CVE-2020-27771","CVE-2020-27772","CVE-2020-27775"],"upstream":["CVE-2020-19667","CVE-2020-25664","CVE-2020-25666","CVE-2020-27751","CVE-2020-27752","CVE-2020-27753","CVE-2020-27754","CVE-2020-27755","CVE-2020-27759","CVE-2020-27760","CVE-2020-27761","CVE-2020-27763","CVE-2020-27765","CVE-2020-27767","CVE-2020-27768","CVE-2020-27769","CVE-2020-27771","CVE-2020-27772","CVE-2020-27775"],"summary":"Security update for ImageMagick","details":"This update for ImageMagick fixes the following issues:\n\t  \n- CVE-2020-19667: Fixed a stack buffer overflow in XPM coder could result in a crash (bsc#1179103).\n- CVE-2020-25664: Fixed a heap-based buffer overflow in PopShortPixel (bsc#1179202).\n- CVE-2020-25666: Fixed an outside the range of representable values of type 'int' and signed integer overflow (bsc#1179212).\n- CVE-2020-27751: Fixed an integer overflow in MagickCore/quantum-export.c (bsc#1179269).\n- CVE-2020-27752: Fixed a heap-based buffer overflow in PopShortPixel in MagickCore/quantum-private.h (bsc#1179346).\n- CVE-2020-27753: Fixed memory leaks in AcquireMagickMemory function (bsc#1179397).\n- CVE-2020-27754: Fixed an outside the range of representable values of type 'long' and signed integer overflow at MagickCore/quantize.c (bsc#1179336).\n- CVE-2020-27755: Fixed memory leaks in ResizeMagickMemory function in ImageMagick/MagickCore/memory.c (bsc#1179345).\n- CVE-2020-27757: Fixed an outside the range of representable values of type 'unsigned long long' at MagickCore/quantum-private.h (bsc#1179268).\n- CVE-2020-27759: Fixed an outside the range of representable values of type 'int' at MagickCore/quantize.c (bsc#1179313).\n- CVE-2020-27760: Fixed a division by zero at MagickCore/enhance.c (bsc#1179281).\n- CVE-2020-27761: Fixed an outside the range of representable values of type 'unsigned long' at coders/palm.c (bsc#1179315).\n- CVE-2020-27763: Fixed a division by zero at MagickCore/resize.c (bsc#1179312).\n- CVE-2020-27765: Fixed a division by zero at MagickCore/segment.c (bsc#1179311).\n- CVE-2020-27767: Fixed an outside the range of representable values of type 'float' at MagickCore/quantum.h (bsc#1179322).\n- CVE-2020-27768: Fixed an outside the range of representable values of type 'unsigned int' at MagickCore/quantum-private.h (bsc#1179339).\n- CVE-2020-27769: Fixed an outside the range of representable values of type 'float' at MagickCore/quantize.c (bsc#1179321).\n- CVE-2020-27771: Fixed an outside the range of representable values of type 'unsigned char' at coders/pdf.c (bsc#1179327).\n- CVE-2020-27772: Fixed an outside the range of representable values of type 'unsigned int' at coders/bmp.c (bsc#1179347).\n- CVE-2020-27775: Fixed an outside the range of representable values of type 'unsigned char' at MagickCore/quantum.h (bsc#1179338).\n","affected":[{"package":{"name":"ImageMagick","ecosystem":"SUSE:Linux Enterprise Point of Sale 11 SP3","purl":"pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.3.6-78.135.1"}]}],"ecosystem_specific":{"binaries":[{"libMagickCore1":"6.4.3.6-78.135.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:14598-1.json"}},{"package":{"name":"ImageMagick","ecosystem":"SUSE:Linux Enterprise Server 11 SP4-LTSS","purl":"pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.3.6-78.135.1"}]}],"ecosystem_specific":{"binaries":[{"libMagickCore1":"6.4.3.6-78.135.1","libMagickCore1-32bit":"6.4.3.6-78.135.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:14598-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2021/suse-su-202114598-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179103"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179202"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179212"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179269"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179281"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179311"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179312"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179313"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179315"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179321"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179322"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179327"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179336"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179338"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179339"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179345"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179346"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179347"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179397"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-19667"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-25664"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-25666"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-27751"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-27752"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-27753"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-27754"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-27755"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-27759"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-27760"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-27761"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-27763"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-27765"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-27767"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-27768"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-27769"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-27771"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-27772"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-27775"}]}