From 0e7c332de8bbd7100f615c8b07569925f6a2e42c Mon Sep 17 00:00:00 2001 From: Thierry Thomas Date: Thu, 13 May 2021 16:17:39 +0200 Subject: [PATCH] security/vuxml: declare vulnerabilities for ImageMagick7 PR: 255802 --- security/vuxml/vuln.xml | 60 ++++++++++++++++++++++++++++++++++++++++- 1 file changed, 59 insertions(+), 1 deletion(-) diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 85df1126f2c96..9e7891c85262a 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -76,8 +76,66 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + ImageMagick7 -- multiple vulnerabilities + + + ImageMagick7 + ImageMagick7-nox11 + 7.0.11-12 + + + + +

CVE reports:

+
+

Several vulnerabilities have been discovered in ImageMagick:

+
    +
  • CVE-2021-20313: A flaw was found in ImageMagick in versions before 7.0.11. + A potential cipher leak when the calculate signatures in TransformSignature is possible.
  • +
  • CVE-2021-20312: A flaw was found in ImageMagick in versions 7.0.11, + where an integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c may trigger + undefined behavior via a crafted image file that is submitted by an attacker and + processed by an application using ImageMagick.
  • +
  • CVE-2021-20311: A flaw was found in ImageMagick in versions before 7.0.11, + where a division by zero in sRGBTransformImage() in the MagickCore/colorspace.c + may trigger undefined behavior via a crafted image file that is submitted by an + attacker processed by an application using ImageMagick.
  • +
  • CVE-2021-20310: A flaw was found in ImageMagick in versions before 7.0.11, + where a division by zero ConvertXYZToJzazbz() of MagickCore/colorspace.c may trigger + undefined behavior via a crafted image file that is submitted by an attacker + and processed by an application using ImageMagick.
  • +
  • CVE-2021-20309: A flaw was found in ImageMagick in versions before 7.0.11, + where a division by zero in WaveImage() of MagickCore/visual-effects.c may trigger + undefined behavior via a crafted image file submitted to an application using ImageMagick.
  • +
  • And several others…
  • +
+
+ +
+ + CVE-2020-27829 + CVE-2020-29599 + CVE-2021-20176 + CVE-2021-20241 + CVE-2021-20243 + CVE-2021-20244 + CVE-2021-20245 + CVE-2021-20246 + CVE-2021-20309 + CVE-2021-20310 + CVE-2021-20311 + CVE-2021-20312 + CVE-2021-20313 + + + 2020-10-27 + 2021-05-13 + +
+ - Pillow -- multiple vulnerabilitie + Pillow -- multiple vulnerabilities py38-pillow