coders/mat.c in ImageMagick 7.0.8-43 Q16 allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by crafting a Matlab image file that is mishandled in ReadImage in MagickCore/constitute.c. Reference: https://github.com/ImageMagick/ImageMagick/issues/1554 Upstream commit: https://github.com/ImageMagick/ImageMagick/commit/f7206618d27c2e69d977abf40e3035a33e5f6be0
Created ImageMagick tracking bugs for this issue: Affects: epel-8 [bug 1767830] Affects: fedora-all [bug 1767829]
Note about GraphicsMagick: This issue was fixed in GraphicsMagick via: http://hg.code.sf.net/p/graphicsmagick/code/rev/233618f8fe82 The fix is available in GraphicsMagick-1.3.31
Fix for ImageMagick6: https://github.com/ImageMagick/ImageMagick6/commit/5caef6e97f3f575cf7bea497865a4c1e624b8010
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-15140