Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 630458 (CVE-2017-14224)

Summary: <media-gfx/imagemagick-{6.9.9.18,7.0.7.6}: Heap buffer overflow in WritePCXImage (CVE-2017-14224)
Product: Gentoo Security Reporter: D'juan McDonald (domhnall) <flopwiki>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: graphics+disabled
Priority: Normal    
Version: unspecified   
Hardware: AMD64   
OS: Linux   
URL: https://github.com/ImageMagick/ImageMagick/issues/733
Whiteboard: B3 [glsa cve]
Package list:
Runtime testing required: ---

Description D'juan McDonald (domhnall) 2017-09-09 10:37:21 UTC
from ${URL}:

A heap-based buffer overflow in WritePCXImage in coders/pcx.c in ImageMagick 7.0.6-8 Q16 allows remote attackers to cause a denial of service or code execution via a crafted file.

Upstream Bug:(https://github.com/ImageMagick/ImageMagick/issues/733)

Upstream Patch 2/2:(
7f2d6fe34d695d3445e2d50937db5541a1b76bde

c6409227c430f114b6425337e64b848535b62e0b
)

CVE Details:(https://nvd.nist.gov/vuln/detail/CVE-2017-14224)

----------------------------------------------------------

Daj Uan (jmbailey/mbailey_j)
Gentoo Security Padawan
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2017-11-11 14:18:06 UTC
This issue was resolved and addressed in
 GLSA 201711-07 at https://security.gentoo.org/glsa/201711-07
by GLSA coordinator Aaron Bauman (b-man).