CVE-2017-14248:(https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-14248) A heap-based buffer over-read in SampleImage() in MagickCore/resize.c in ImageMagick 7.0.6-8 Q16 allows remote attackers to cause a denial of service via a crafted file. Upstream Bug:(https://github.com/ImageMagick/ImageMagick/issues/717) Upstream Patch 1/1:(commit c5402b6e0fcf8b694ae2af6a6652ebb8ce0ccf46) ------------------------------------------------------------------------- CVE-2017-14249:(https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-14249) ImageMagick 7.0.6-8 Q16 mishandles EOF checks in ReadMPCImage in coders/mpc.c, leading to division by zero in GetPixelCacheTileSize in MagickCore/cache.c, allowing remote attackers to cause a denial of service via a crafted file. Upstream Bug:(https://github.com/ImageMagick/ImageMagick/issues/708) Upstream Patch 2/2:( IM7 https://github.com/ImageMagick/ImageMagick/commit/2071d67ebf729f76d73c33c1152df4816d1d79ac IM6 https://github.com/ImageMagick/ImageMagick/commit/66112b7a7b64f688efe6fec53a829874a74dea04 ) ------------------------------------------------------------------- Daj Uan (jmbailey/mbailey_j) Gentoo Security Padawan
Fixed in Gentoo via https://github.com/gentoo/gentoo/commit/e55c500d5efec48f8fb7aa3da8b27b9dc0b30dbf#diff-c3da9b5318c1a67d6927fb8032d46fe5
This issue was resolved and addressed in GLSA 201711-07 at https://security.gentoo.org/glsa/201711-07 by GLSA coordinator Aaron Bauman (b-man).