In ImageMagick 7.0.7-4 Q16, an out of bounds read flaw related to ReadTIFFImage has been reported in coders/tiff.c. An attacker could possibly exploit this flaw to disclose potentially sensitive memory or cause an application crash.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.debian.org/security/2017/dsa-4040 | third party advisory vendor advisory |
https://usn.ubuntu.com/3681-1/ | third party advisory vendor advisory |
https://www.debian.org/security/2017/dsa-4032 | third party advisory vendor advisory |
https://github.com/ImageMagick/ImageMagick/issues/765 | issue tracking third party advisory patch |
http://www.securityfocus.com/bid/100944 | vdb entry third party advisory |