From $URL: In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c. This is caused by an incomplete fix of CVE-2017-9144. Upstream reference: https://github.com/ImageMagick/ImageMagick/issues/502 Upstream fix (ImageMagick-7): https://github.com/ImageMagick/ImageMagick/commit/86cb33143c5b21912187403860a7c26761a3cd23 Upstream fix (ImageMagick-6): https://github.com/ImageMagick/ImageMagick/commit/7f1f01b695e869c410ee10e2176f8fd764f09373 MITRE has assigned CVE-2017-11352 for this issue.
@ Arches, please test and mark stable: =media-gfx/imagemagick-6.9.9.0
ia64 stable
arm stable
Stable on amd64.
x86 stable
alpha stable
PPC / PPC please complete stabilization on this security bug.
hppa/sparc stable (tested by Dakon)
stable 6.9.9.0 for ppc/ppc64 Last arches are done.
Thank you. @Maintainers please drop vulnerable versions. @Security please vote. Gentoo Security Padawan ChrisADR
GLSA Vote: No Tree is clean.