Summary: | media-gfx/imagemagick: heap-based buffer overflow in IsPixelMonochrome (pixel-accessor.h) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED CANTFIX | ||
Severity: | minor | CC: | graphics+disabled |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://blogs.gentoo.org/ago/2016/10/07/imagemagick-heap-based-buffer-overflow-in-ispixelmonochrome-pixel-accessor-h/ | ||
Whiteboard: | ~3 [noglsa cve] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 602044 | ||
Bug Blocks: |
Description
Agostino Sarubbo
![]() CVE ID: CVE-2016-8678 Summary: The IsPixelMonochrome function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.0 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted file. NOTE: the vendor says "This is a Q64 issue and we do not support Q64." Published: 2017-02-15T21:59:00.000Z Upstream bug: https://github.com/ImageMagick/ImageMagick/issues/272 Only affecting unsupported QuantumDepth=64 build. |