In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to cause a denial of service or possibly information disclosure via a crafted image file.
Upstream issue:
https://github.com/ImageMagick/ImageMagick/issues/1555
Created GraphicsMagick tracking bugs for this issue:
Affects: epel-all [bug 1705407]
Affects: fedora-all [bug 1705408]
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1705409]
Comment 2Riccardo Schirone
2019-05-10 09:52:47 UTC