A flaw was found in ImageMagick 7.0.7-26 Q16. An excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of minutes) with a tiny PoC file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tiff file.
References: https://github.com/ImageMagick/ImageMagick/issues/1072
Patch: https://github.com/ImageMagick/ImageMagick/commit/089fca04e0130549fa15f48ace3f56e30a06049a
Last updated 24 July 2024
A flaw was found in ImageMagick 7.0.7-25 Q16. WriteEPTImage function in coders/ept.c allows remote attackers to cause a denial of service (MagickCore/memory.c double free and application crash) or possibly have unspecified other impact via a crafted file.
Reference: https://github.com/ImageMagick/ImageMagick/issues/1025
Patch: https://github.com/ImageMagick/ImageMagick/commit/6355db269e03f879c516cf9d592c72e157bc75d6
In the ReadDCMImage function in coders/dcm.c in ImageMagick before 7.0 ...
ImageMagick 7.0.7-22 Q16 has memory leaks in the ReadDCMImage function in coders/dcm.c.
ImageMagick 7.0.7-22 Q16 has memory leaks in the EncodeImageAttributes function in coders/json.c, as demonstrated by the ReadPSDLayersInternal function in coders/psd.c.
As per upstream samba advisory:
All versions of Samba from 3.5.0 to 4.2.0rc4 are vulnerable to an unexpected code execution vulnerability in the smbd file server daemon.
A malicious client could send packets that may set up the stack in such a way that the freeing of memory in a subsequent anonymous netlogon packet could allow execution of arbitrary code. This code would execute with root privileges.
Buffer overflow in the mpoverridelegacyirq() function in arch/x86/kernel/acpi/boot.c in the Linux kernel through 3.2 allows local users to gain privileges via a crafted ACPI table.
In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in t ...
In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in t ...
In ImageMagick 7.0.6-10, a NULL Pointer Dereference issue is present in the ReadCUTImage function in coders/cut.c that could allow an attacker to cause a Denial of Service (in the QueueAuthenticPixelCacheNexus function within the MagickCore/cache.c file) by submitting a malformed image file.
ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability i ...
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
ImageMagick 7.0.7-17 Q16 x8664 has memory leaks in coders/msl.c, related to MSLPopImage and ProcessMSLScript, and associated with mishandling of MSLPushImage calls.
In ImageMagick 7.0.7-12 Q16, a memory leak vulnerability was found in ...
In ImageMagick 7.0.7-16 Q16, a memory leak vulnerability was found in ...
In ImageMagick 7.0.7-12 Q16, an infinite loop vulnerability was found ...
In ImageMagick 7.0.7-12 Q16, a memory leak vulnerability was found in the function ReadXPMImage in coders/xpm.c, which allows attackers to cause a denial of service via a crafted xpm image file.
ImageMagick 7.0.7-2 has a memory leak in ReadSGIImage in coders/sgi.c.
ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability i ...
ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability i ...
ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability i ...
ImageMagick version 7.0.7-2 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.
ImageMagick 7.0.6-6 has a memory exhaustion vulnerability in ReadWPGIm ...
ImageMagick 7.0.6-6 has a memory leak vulnerability in ReadXCFImage in ...
ImageMagick 7.0.7-0 has a memory exhaustion issue in ReadSUNImage in coders/sun.c.
ImageMagick 7.0.7-0 has a NULL Pointer Dereference in TIFFIgnoreTags in coders/tiff.c.
ImageMagick 7.0.6-6 has a memory leak in ReadMATImage in coders/mat.c.