[Pkg-gmagick-im-team] Bug#859025: imagemagick: CVE-2017-7275

Salvatore Bonaccorso carnil at debian.org
Wed Mar 29 16:33:14 UTC 2017


Source: imagemagick
Severity: minor
Tags: security upstream

Hi,

the following vulnerability was published for imagemagick.

CVE-2017-7275[0]:
| The ReadPCXImage function in coders/pcx.c in ImageMagick 7.0.4.9 allows
| remote attackers to cause a denial of service (attempted large memory
| allocation and application crash) via a crafted file. NOTE: this
| vulnerability exists because of an incomplete fix for CVE-2016-8862 and
| CVE-2016-8866.

NOTE: I'm opening still a bug for this, since it is unclear if that's
really a problem. Upstream is not able to reproduce the issue, and it
might be an issue on the reporter side.

For now the issue is marked as 'non-issue' in the security-tracker,
but in case more details and reproducibility is given of the issue,
and patch of upstream available, we might go forward and reevaluate
this.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-7275
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7275
[1] https://github.com/ImageMagick/ImageMagick/issues/271

Regards,
Salvatore



More information about the Pkg-gmagick-im-team mailing list