The WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (assertion failure and crash) via vectors related to a ReferenceBlob and a NULL pointer.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
http://www.debian.org/security/2016/dsa-3746 | vendor advisory |
http://www.openwall.com/lists/oss-security/2016/10/07/4 | mailing list third party advisory patch |
http://www.openwall.com/lists/oss-security/2016/10/08/5 | third party advisory mailing list |
http://www.securityfocus.com/bid/93467 | vdb entry third party advisory |