A flaw was found in ImageMagick 7.0.7-37 Q16, SetGrayscaleImage in the quantize.c file allows attackers to cause a heap-based buffer over-read via a crafted file. References: https://github.com/ImageMagick/ImageMagick/issues/1156 Patch: https://github.com/ImageMagick/ImageMagick/commit/5294966898532a6bd54699fbf04edf18902513ac
Created ImageMagick tracking bugs for this issue: Affects: fedora-all [bug 1584905]
Statement: This issue did not affect the versions of ImageMagick as shipped with Red Hat Enterprise Linux 5, 6, and 7.