
CVE-2017-15217 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-15217
10 Oct 2017 — ImageMagick 7.0.7-2 has a memory leak in ReadSGIImage in coders/sgi.c. ImageMagick 7.0.7-2 tiene una fuga de memoria en ReadSGIImage en coders/sgi.c. It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privileges of the user invoking the program. • http://www.securityfocus.com/bid/101231 • CWE-772: Missing Release of Resource after Effective Lifetime •

CVE-2017-15218 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-15218
10 Oct 2017 — ImageMagick 7.0.7-2 has a memory leak in ReadOneJNGImage in coders/png.c. ImageMagick 7.0.7-2 tiene una fuga de memoria en ReadOneJNGImage en coders/png.c. It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privileges of the user invoking the program. • http://www.securityfocus.com/bid/101233 • CWE-772: Missing Release of Resource after Effective Lifetime •

CVE-2017-15032 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-15032
05 Oct 2017 — ImageMagick version 7.0.7-2 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c. ImageMagick 7.0.7-2 tiene una vulnerabilidad de fuga de memoria en ReadYCBCRImage en coders/ycbcr.c. It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privileges of the user invoking the progra... • https://github.com/ImageMagick/ImageMagick/commit/241988ca28139ad970c1d9717c419f41e360ddb0 • CWE-772: Missing Release of Resource after Effective Lifetime •

CVE-2017-15033 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-15033
05 Oct 2017 — ImageMagick version 7.0.7-2 contains a memory leak in ReadYUVImage in coders/yuv.c. ImageMagick 7.0.7-2 tiene una vulnerabilidad de fuga de memoria en ReadYUVImage in coders/yuv.c. It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privileges of the user invoking the program. • https://github.com/ImageMagick/ImageMagick/commit/ef8f40689ac452398026c07da41656a7c87e4683 • CWE-772: Missing Release of Resource after Effective Lifetime •

CVE-2017-15015 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-15015
04 Oct 2017 — ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in PDFDelegateMessage in coders/pdf.c. ImageMagick 7.0.7-0 Q16 tiene una vulnerabilidad de desreferencia de puntero NULL en PDFDelegatesMessage en coders/pdf.c. It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the p... • https://github.com/ImageMagick/ImageMagick/issues/724 • CWE-476: NULL Pointer Dereference •

CVE-2017-15016 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-15016
04 Oct 2017 — ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in ReadEnhMetaFile in coders/emf.c. ImageMagick 7.0.7-0 Q16 tiene una vulnerabilidad de desreferencia de puntero NULL en ReadEnhMetaFile en coders/emf.c. It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privileg... • https://github.com/ImageMagick/ImageMagick/issues/725 • CWE-476: NULL Pointer Dereference •

CVE-2017-15017 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-15017
04 Oct 2017 — ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in ReadOneMNGImage in coders/png.c. ImageMagick 7.0.7-0 Q16 tiene una vulnerabilidad de desreferencia de puntero NULL en ReadOneMNGImag en coders/png.c. It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privilege... • https://github.com/ImageMagick/ImageMagick/issues/723 • CWE-476: NULL Pointer Dereference •

CVE-2017-13704
https://notcve.org/view.php?id=CVE-2017-13704
02 Oct 2017 — In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash. En las versiones anteriores a la 2.78 de dnsmasq, si el tamaño del paquete DNS no coincide con el tamaño esperado, el parámetro size en una llamada memset obtiene un valor negativo. Como es un valor sin signo, memset acaba escribiend... • http://thekelleys.org.uk/dnsmasq/CHANGELOG • CWE-20: Improper Input Validation •

CVE-2017-14491 – Dnsmasq < 2.78 - 2-byte Heap Overflow
https://notcve.org/view.php?id=CVE-2017-14491
02 Oct 2017 — Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response. Un desbordamiento de búfer basado en memoria dinámica (heap) en dnsmasq en versiones anteriores a la 2.78 permite a los atacantes provocar una denegación de servicio (cierre inesperado) o ejecutar código arbitrario utilizando una respuesta DNS manipulada. A heap buffer overflow was found in dnsmasq in the code responsible for building DNS replie... • https://packetstorm.news/files/id/144480 • CWE-122: Heap-based Buffer Overflow CWE-787: Out-of-bounds Write •

CVE-2017-14492 – Dnsmasq < 2.78 - Heap Overflow
https://notcve.org/view.php?id=CVE-2017-14492
02 Oct 2017 — Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement request. Un desbordamiento de búfer basado en memoria dinámica (heap) en dnsmasq en versiones anteriores a la 2.78 permite a los atacantes provocar una denegación de servicio (cierre inesperado) o ejecutar código arbitrario mediante una petición manipulada de anuncio de router IPv6. A heap buffer overflow was discovered in dnsmasq in... • https://packetstorm.news/files/id/144479 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-122: Heap-based Buffer Overflow •