Security update for ImageMagick

Announcement ID: SUSE-SU-2016:1301-1
Rating: important
References:
Cross-References:
CVSS scores:
  • CVE-2016-3714 ( NVD ): 8.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products:
  • SLES for SAP Applications 11-SP4
  • SUSE Cloud 5
  • SUSE Linux Enterprise Server 11 SP2 LTSS 11-SP2
  • SUSE Linux Enterprise Server 11 SP3 LTSS 11-SP3
  • SUSE Linux Enterprise Server 11 SP4
  • SUSE Linux Enterprise Software Development Kit 11 SP4
  • SUSE Manager Proxy 2.1
  • SUSE Manager Server 2.1

An update that solves one vulnerability can now be installed.

Description:

This update for ImageMagick fixes the following issues:

  • bsc#978061: A vulnerability in ImageMagick's "https" module allowed users to execute arbitrary shell commands on the host performing the image conversion. The issue had the potential for remote command injection. This update mitigates the vulnerability by disabling all access to the "https" module in the "delegates.xml" config file. (CVE-2016-3714)

Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • SUSE Linux Enterprise Software Development Kit 11 SP4
    zypper in -t patch sdksp4-ImageMagick-12560=1
  • SUSE Linux Enterprise Server 11 SP2 LTSS 11-SP2
    zypper in -t patch slessp2-ImageMagick-12560=1
  • SUSE Linux Enterprise Server 11 SP3 LTSS 11-SP3
    zypper in -t patch slessp3-ImageMagick-12560=1
  • SUSE Linux Enterprise Server 11 SP4
    zypper in -t patch slessp4-ImageMagick-12560=1
  • SLES for SAP Applications 11-SP4
    zypper in -t patch slessp4-ImageMagick-12560=1
  • SUSE Cloud 5
    zypper in -t patch sleclo50sp3-ImageMagick-12560=1
  • SUSE Manager Server 2.1
    zypper in -t patch sleman21-ImageMagick-12560=1
  • SUSE Manager Proxy 2.1
    zypper in -t patch slemap21-ImageMagick-12560=1

Package List:

  • SUSE Linux Enterprise Software Development Kit 11 SP4 (s390x x86_64 i586 ppc64 ia64)
    • ImageMagick-6.4.3.6-7.37.1
    • perl-PerlMagick-6.4.3.6-7.37.1
    • libMagickWand1-6.4.3.6-7.37.1
    • ImageMagick-devel-6.4.3.6-7.37.1
    • libMagick++-devel-6.4.3.6-7.37.1
    • libMagick++1-6.4.3.6-7.37.1
  • SUSE Linux Enterprise Software Development Kit 11 SP4 (ppc64 s390x x86_64)
    • libMagickWand1-32bit-6.4.3.6-7.37.1
  • SUSE Linux Enterprise Server 11 SP2 LTSS 11-SP2 (s390x x86_64 i586)
    • libMagickCore1-6.4.3.6-7.37.1
  • SUSE Linux Enterprise Server 11 SP2 LTSS 11-SP2 (s390x x86_64)
    • libMagickCore1-32bit-6.4.3.6-7.37.1
  • SUSE Linux Enterprise Server 11 SP3 LTSS 11-SP3 (s390x x86_64 i586)
    • libMagickCore1-6.4.3.6-7.37.1
  • SUSE Linux Enterprise Server 11 SP3 LTSS 11-SP3 (s390x x86_64)
    • libMagickCore1-32bit-6.4.3.6-7.37.1
  • SUSE Linux Enterprise Server 11 SP4 (s390x x86_64 i586 ppc64 ia64)
    • libMagickCore1-6.4.3.6-7.37.1
  • SUSE Linux Enterprise Server 11 SP4 (ppc64 s390x x86_64)
    • libMagickCore1-32bit-6.4.3.6-7.37.1
  • SLES for SAP Applications 11-SP4 (ppc64 x86_64)
    • libMagickCore1-6.4.3.6-7.37.1
    • libMagickCore1-32bit-6.4.3.6-7.37.1
  • SUSE Cloud 5 (x86_64)
    • libMagickCore1-6.4.3.6-7.37.1
    • libMagickCore1-32bit-6.4.3.6-7.37.1
  • SUSE Manager Server 2.1 (s390x x86_64)
    • libMagickCore1-6.4.3.6-7.37.1
    • libMagickCore1-32bit-6.4.3.6-7.37.1
  • SUSE Manager Proxy 2.1 (x86_64)
    • libMagickCore1-6.4.3.6-7.37.1
    • libMagickCore1-32bit-6.4.3.6-7.37.1

References: