The AcquireResampleFilterThreadSet function in magick/resample-private.h in ImageMagick 7.0.7-4 mishandles failed memory allocation, which allows remote attackers to cause a denial of service (NULL Pointer Dereference in DistortImage in MagickCore/distort.c, and application crash) via unspecified vectors.
References
Configurations
History
21 Nov 2024, 03:13
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/ImageMagick/ImageMagick/issues/780 - Issue Tracking, Patch, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2019/05/msg00015.html - | |
References | () https://lists.debian.org/debian-lts-announce/2020/09/msg00007.html - | |
References | () https://usn.ubuntu.com/3681-1/ - |
Information
Published : 2017-09-26 02:29
Updated : 2024-11-21 03:13
NVD link : CVE-2017-14739
Mitre link : CVE-2017-14739
CVE.ORG link : CVE-2017-14739
JSON object : View
Products Affected
imagemagick
- imagemagick
CWE
CWE-476
NULL Pointer Dereference