Out-of-bounds read In imagemagick
Description
ImageMagick has heap buffer overflow in WriteXWDImage due to CARD32 arithmetic overflow in bytes_per_line calculation A 32-bit unsigned integer overflow in the XWD (X Windows) encoder can cause an undersized heap buffer allocation. When writing a extremely large image an out of bounds heap write can occur.
================================================================= ==741961==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x5020000083dc at pc 0x56553b4c4245 bp 0x7ffd9d20fef0 sp 0x7ffd9d20fee0 WRITE of size 1 at 0x5020000083dc thread T0
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 8:6.9.11.60+dfsg-1.3+deb11u11 | ||
debian 12 | 8:6.9.11.60+dfsg-1.6+deb12u8 | ||
debian 13 | 8:7.1.1.43+dfsg1-1+deb13u7 | ||
debian 14 | 8:7.1.2.16+dfsg1-1 | ||
nuget | 14.10.4 | ||
nuget | 14.10.4 | ||
nuget | 14.10.4 | ||
nuget | 14.10.4 | ||
nuget | 14.10.4 | ||
nuget | 14.10.4 |
1-10 of 25
10
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1.