Red Hat Bugzilla – Bug 1594339
CVE-2018-12600 ImageMagick: out of bounds write ReadDIBImage and WriteDIBImage in coders/dib.c
Last modified: 2018-08-02 07:04:53 EDT
A flaw was found in ImageMagick 7.0.8-3 Q16, ReadDIBImage and WriteDIBImage in coders/dib.c allow attackers to cause an out of bounds write via a crafted file. References: https://github.com/ImageMagick/ImageMagick/issues/1178 Patch: https://github.com/ImageMagick/ImageMagick6/commit/ae71c12bbaa34d942e036824ff389c22b7dacade https://github.com/ImageMagick/ImageMagick/commit/921f208c2ea3cc45847f380257f270ff424adfff
Created ImageMagick tracking bugs for this issue: Affects: fedora-all [bug 1594421]
When writing a DIB file, ImageMagick incorrectly allocates the pixels array on the heap, using the wrong size. When converting a crafted image file to the DIB format, this flaw could be used to write beyond the limits, overwriting other data on the heap and causing a Denial of Service or other unspecified effects.