ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left waiting for stdin input.
The product does not release or incorrectly releases a resource before it is made available for re-use.
Link | Tags |
---|---|
https://imagemagick.org/ | product |
https://www.metabaseq.com/imagemagick-zero-days/ | third party advisory exploit |
https://www.debian.org/security/2023/dsa-5347 | vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZZLLS37P67CMBRML6OCG42GPCKGRCJNV/ | vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AINSUL2QBKETGYRPA7XSCMJWLUB44M6S/ | vendor advisory |
https://lists.debian.org/debian-lts-announce/2023/03/msg00008.html | mailing list |