Possible out-of-bounds write in ReadDCMImage() function due to lack of validation of pixel.red, pixel.green, and pixel.blue. Upstream fix: https://github.com/ImageMagick/ImageMagick/commit/5511ef530576ed18fd636baa3bb4eda3d667665d External References: https://blog.fuzzing-project.org/46-Various-invalid-memory-reads-in-ImageMagick-WPG,-DDS,-DCM.html CVE assignment: http://seclists.org/oss-sec/2016/q2/564
Created ImageMagick tracking bugs for this issue: Affects: fedora-all [bug 1348173]