From ${URL}: In ImageMagick before 6.9.9-3 and 7.x before 7.0.6-3, there is a missing NULL check in the ReadMATImage function in coders/mat.c, leading to a denial of service (assertion failure and application exit) in the DestroyImageInfo function in MagickCore/image.c. CVE Details: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-13658 Upstream Bug:https://github.com/ImageMagick/ImageMagick/issues/598 Upstream Patch: https://github.com/ImageMagick/ImageMagick/commit/ac38f521356b576ab57c2e74cc541548d80a8bdc
@maintainer(s), after bump, please follow procedure to stabilize if needed and close on report, thank you. Daj'Uan (mbailey_j) Gentoo Security Scout
Upstream Bug: https://github.com/ImageMagick/ImageMagick/issues/599 Upstream Bug: https://github.com/ImageMagick/ImageMagick/issues/598 commit e5c063a1007506ba69e97a35effcdef944421c89 commit 82b53bd74df1489332e4043035a51b43f54d43f1 commit 7d3af83d8b946f952bfd028451e6dfb1f7ace07a @maintainer(s), above patches were pushed under incorrect ticket upstream. All patches in OUR ticket here apply to same CVE. Daj Uan (jmbailey/mbailey_j) Gentoo Security Padawan