ISOMAN

CVE

CVE-2017-14060

In ImageMagick 7.0.6-10, a NULL Pointer Dereference issue is present in the ReadCUTImage function in coders/cut.c that could allow an attacker to cause a Denial of Service (in the QueueAuthenticPixelCacheNexus function within the MagickCore/cache.c file) by submitting a malformed image file.

Severity
MEDIUM
CVSS
6.5
Published
Modified

Linked Releases

References

  1. https://github.com/ImageMagick/ImageMagick/issues/710
  2. https://lists.debian.org/debian-lts-announce/2019/05/msg00015.html
  3. https://lists.debian.org/debian-lts-announce/2020/09/msg00007.html
  4. https://security.gentoo.org/glsa/201711-07
  5. https://usn.ubuntu.com/3681-1/
  6. https://github.com/ImageMagick/ImageMagick/issues/710
  7. https://lists.debian.org/debian-lts-announce/2019/05/msg00015.html
  8. https://lists.debian.org/debian-lts-announce/2020/09/msg00007.html
  9. https://security.gentoo.org/glsa/201711-07
  10. https://usn.ubuntu.com/3681-1/