The ReadDCMImage function in coders\dcm.c in ImageMagick 7.0.6-1 has an integer signedness error leading to excessive memory consumption via a crafted DCM file.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://usn.ubuntu.com/3681-1/ | vendor advisory |
https://security.gentoo.org/glsa/201711-07 | vendor advisory |
http://www.securityfocus.com/bid/100096 | vdb entry |
https://github.com/ImageMagick/ImageMagick/issues/533 | issue tracking third party advisory patch |
https://lists.debian.org/debian-lts-announce/2019/05/msg00015.html | mailing list |
https://lists.debian.org/debian-lts-announce/2020/09/msg00007.html | mailing list |