In the ReadDCMImage function in coders/dcm.c in ImageMagick before 7.0.7-23, each redmap, greenmap, and bluemap variable can be overwritten by a new pointer. The previous pointer is lost, which leads to a memory leak. This allows remote attackers to cause a denial of service.
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
Link | Tags |
---|---|
https://usn.ubuntu.com/3681-1/ | third party advisory vendor advisory |
https://github.com/ImageMagick/ImageMagick/issues/964 | patch exploit third party advisory issue tracking |