A flaw was found in ImageMagick before version 7.0.11. A integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c may trigger undefined behavior via crafted image file. Upstream patch: https://github.com/ImageMagick/ImageMagick/commit/70aa86f5d5d8aa605a918ed51f7574f433a18482
Created ImageMagick tracking bugs for this issue: Affects: epel-8 [bug 1946743] Affects: fedora-all [bug 1946744]
Statement: This flaw is out of support scope for Red Hat Enterprise Linux 6 and 7. It does not affect Red Hat Enterprise Linux 8 because the ImageMagick package is not shipped. To learn more about Red Hat Enterprise Linux support scope, please see https://access.redhat.com/support/policy/updates/errata/ .