Red Hat Bugzilla – Bug 1500013
CVE-2017-14684 ImageMagick: Memory leak in the function ReadVIPSImage
Last modified: 2017-10-09 12:00:29 EDT
In ImageMagick 7.0.7-4 Q16, a memory leak vulnerability was found in the function ReadVIPSImage in coders/vips.c, which allows attackers to cause a denial of service (memory consumption in ResizeMagickMemory in MagickCore/memory.c) via a crafted file. Upstream issue: https://github.com/ImageMagick/ImageMagick/issues/770 Upstream patch: https://github.com/ImageMagick/ImageMagick/commit/dd367e0c3c3f37fbf1c20fa107b67a668b22c6e2