Improper resource allocation In magick.net-q16-openmp-x64
Description
ImageMagick has a Stack Overflow in DestroyXMLTree()
Magick frees the memory of the XML tree via the DestroyXMLTree function; however, this process is executed recursively with no depth limit imposed. When magick processes an XML file with deeply nested structures, it will exhaust the stack memory, resulting in a Denial of Service (DoS) attack.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
nuget | 14.12.0 | ||
debian 13 | 8:7.1.1.43+dfsg1-1+deb13u8 | ||
debian 12 | 8:6.9.11.60+dfsg-1.6+deb12u9 | ||
nuget | 14.12.0 | ||
nuget | 14.12.0 | ||
nuget | 14.12.0 | ||
nuget | 14.12.0 | ||
nuget | 14.12.0 | ||
nuget | 14.12.0 | ||
nuget | 14.12.0 |
1-10 of 23
10
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4.