Bug 1581485 (CVE-2017-18272) - CVE-2017-18272 ImageMagick: use-after-free in ReadOneMNGImage function in coders/png.c
Summary: CVE-2017-18272 ImageMagick: use-after-free in ReadOneMNGImage function in cod...
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2017-18272
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1581487 1581490 1585901
Blocks: 1581491
TreeView+ depends on / blocked
 
Reported: 2018-05-22 22:44 UTC by Laura Pardo
Modified: 2021-02-17 00:16 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2019-06-10 10:26:18 UTC
Embargoed:


Attachments (Terms of Use)

Description Laura Pardo 2018-05-22 22:44:20 UTC
A flaw was found in ImageMagick 7.0.7-16 Q16 x86_64 2017-12-25, there is a use-after-free in ReadOneMNGImage in coders/png.c, which allows attackers to cause a denial of service via a crafted MNG image file that is mishandled in an MngInfoDiscardObject call.


References:
https://github.com/ImageMagick/ImageMagick/issues/918

Patch:
https://github.com/ImageMagick/ImageMagick/commit/93d029b70ac766ce0b5d7261a2dd334535f48038

Comment 1 Laura Pardo 2018-05-22 22:46:14 UTC
Created ImageMagick tracking bugs for this issue:

Affects: fedora-all [bug 1581487]

Comment 3 Pedro Yóssis Silva Barbosa 2018-06-05 04:16:11 UTC
The ReadOneMNGImage function is included in recent versions of ImageMagick only.

Comment 4 Pedro Yóssis Silva Barbosa 2018-06-05 04:16:19 UTC
Statement:

This issue did not affect the versions of ImageMagick as shipped with Red Hat Enterprise Linux 5, 6, and 7.


Note You need to log in before you can comment on or make changes to this bug.