In ImageMagick before 6.9.9-4 and 7.x before 7.0.6-4, a crafted file could trigger a memory leak in ReadOnePNGImage in coders/png.c.
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
Link | Tags |
---|---|
https://security.gentoo.org/glsa/201711-07 | vendor advisory |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=870116 | issue tracking third party advisory |
https://github.com/ImageMagick/ImageMagick/issues/600 | third party advisory patch |
https://www.debian.org/security/2017/dsa-4019 | vendor advisory |