In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in WritePDFImage in coders/pdf.c.
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/106847 | vdb entry third party advisory |
https://github.com/ImageMagick/ImageMagick/issues/1454 | exploit third party advisory patch |
http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/11ad3aeb8ab1 | third party advisory patch |
https://github.com/ImageMagick/ImageMagick/commit/306c1f0fa5754ca78efd16ab752f0e981d4f6b82 | third party advisory patch |
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00034.html | broken link third party advisory vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00006.html | vendor advisory broken link |
https://usn.ubuntu.com/4034-1/ | third party advisory vendor advisory |
https://www.debian.org/security/2020/dsa-4712 | third party advisory vendor advisory |