ImageMagick 7.0.8-50 Q16 has direct memory leaks in AcquireMagickMemory because of an error in CLIListOperatorImages in MagickWand/operation.c for a NULL value.
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Link | Tags |
---|---|
https://github.com/ImageMagick/ImageMagick/issues/1604 | issue tracking patch exploit third party advisory |
https://github.com/ImageMagick/ImageMagick/commit/ce08a3691a8ac29125e29fc41967b3737fa3f425 | patch |
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00069.html | mailing list third party advisory vendor advisory |