In ImageMagick 7.0.7-12 Q16, a memory leak vulnerability was found in the function ReadXPMImage in coders/xpm.c, which allows attackers to cause a denial of service via a crafted xpm image file.
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
Link | Tags |
---|---|
https://github.com/ImageMagick/ImageMagick/issues/873 | patch third party advisory exploit |
http://www.securityfocus.com/bid/102203 | third party advisory vdb entry |
https://usn.ubuntu.com/3681-1/ | third party advisory vendor advisory |