Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 630458 (CVE-2017-14224) - <media-gfx/imagemagick-{6.9.9.18,7.0.7.6}: Heap buffer overflow in WritePCXImage (CVE-2017-14224)
Summary: <media-gfx/imagemagick-{6.9.9.18,7.0.7.6}: Heap buffer overflow in WritePCXIm...
Status: RESOLVED FIXED
Alias: CVE-2017-14224
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: AMD64 Linux
: Normal minor
Assignee: Gentoo Security
URL: https://github.com/ImageMagick/ImageM...
Whiteboard: B3 [glsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-09-09 10:37 UTC by D'juan McDonald (domhnall)
Modified: 2017-11-11 14:18 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description D'juan McDonald (domhnall) 2017-09-09 10:37:21 UTC
from ${URL}:

A heap-based buffer overflow in WritePCXImage in coders/pcx.c in ImageMagick 7.0.6-8 Q16 allows remote attackers to cause a denial of service or code execution via a crafted file.

Upstream Bug:(https://github.com/ImageMagick/ImageMagick/issues/733)

Upstream Patch 2/2:(
7f2d6fe34d695d3445e2d50937db5541a1b76bde

c6409227c430f114b6425337e64b848535b62e0b
)

CVE Details:(https://nvd.nist.gov/vuln/detail/CVE-2017-14224)

----------------------------------------------------------

Daj Uan (jmbailey/mbailey_j)
Gentoo Security Padawan
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2017-11-11 14:18:06 UTC
This issue was resolved and addressed in
 GLSA 201711-07 at https://security.gentoo.org/glsa/201711-07
by GLSA coordinator Aaron Bauman (b-man).