Hide Forgot
ImageMagick through version 7.0.7-28 is vulnerable to an infinite loop in coders/png.c:ReadOneMNGImage(). An attacker could exploit this to cause a denial of service via crafted MNG file. References: https://github.com/ImageMagick/ImageMagick/issues/1095
Created ImageMagick tracking bugs for this issue: Affects: fedora-all [bug 1572045]
Upstream commit: https://github.com/ImageMagick/ImageMagick6/commit/9eda4b36a8695e4a0cd27bea28b9c173c68a01ec
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2018-10177