In ImageMagick before 6.9.8-8 and 7.x before 7.0.5-9, the ReadJP2Image function in coders/jp2.c does not properly validate the channel geometry, leading to a crash.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://github.com/ImageMagick/ImageMagick/commit/acee073df34aa4d491bf5cb74d3a15fc80f0a3aa | patch third party advisory issue tracking |
https://usn.ubuntu.com/3681-1/ | third party advisory vendor advisory |
https://security.gentoo.org/glsa/201711-07 | third party advisory vendor advisory |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=869830 | third party advisory issue tracking |
https://www.debian.org/security/2017/dsa-4019 | third party advisory vendor advisory |
https://github.com/ImageMagick/ImageMagick/issues/501 | patch third party advisory issue tracking |
https://lists.debian.org/debian-lts-announce/2019/05/msg00015.html | third party advisory mailing list |
https://github.com/ImageMagick/ImageMagick/commit/f13c6b54a879aaa771ec64b5a066b939e8f8e7f0 | patch vendor advisory |