In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function GetImagePixelCache in MagickCore/cache.c, which allows attackers to cause a denial of service via a crafted CALS image file.
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
Link | Tags |
---|---|
https://usn.ubuntu.com/3681-1/ | third party advisory vendor advisory |
https://github.com/ImageMagick/ImageMagick/issues/930 | issue tracking exploit third party advisory |