WriteEPTImage in coders/ept.c in ImageMagick 7.0.7-25 Q16 allows remote attackers to cause a denial of service (MagickCore/memory.c double free and application crash) or possibly have unspecified other impact via a crafted file.
The product calls free() twice on the same memory address.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/103498 | vdb entry third party advisory |
https://usn.ubuntu.com/3681-1/ | third party advisory vendor advisory |
https://github.com/ImageMagick/ImageMagick/issues/1025 | issue tracking third party advisory |
https://lists.debian.org/debian-lts-announce/2020/08/msg00030.html | mailing list |