
CVE-2017-17887 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-17887
24 Dec 2017 — In ImageMagick 7.0.7-16 Q16, a memory leak vulnerability was found in the function GetImagePixelCache in magick/cache.c, which allows attackers to cause a denial of service via a crafted MNG image file that is processed by ReadOneMNGImage. Se ha encontrado una vulnerabilidad de filtrado de memoria en ImageMagick 7.0.7-16 Q16 en la función GetImagePixelCache en magick/cache.c. Esta vulnerabilidad permite que los atacantes provoquen una denegación de servicio mediante un archivo de imagen MNG manipulado que e... • https://github.com/ImageMagick/ImageMagick/issues/903 • CWE-772: Missing Release of Resource after Effective Lifetime •

CVE-2017-17680 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-17680
14 Dec 2017 — In ImageMagick 7.0.7-12 Q16, a memory leak vulnerability was found in the function ReadXPMImage in coders/xpm.c, which allows attackers to cause a denial of service via a crafted xpm image file. Se ha encontrado una vulnerabilidad de filtrado de memoria en ImageMagick 7.0.7-12 Q16 en la función ReadXPMImage en coders/xpm.c. Esta vulnerabilidad permite que los atacantes provoquen una denegación de servicio mediante un archivo de imagen xpm manipulado. It was discovered that ImageMagick incorrectly handled ce... • http://www.securityfocus.com/bid/102203 • CWE-772: Missing Release of Resource after Effective Lifetime •

CVE-2017-17681 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-17681
14 Dec 2017 — In ImageMagick 7.0.7-12 Q16, an infinite loop vulnerability was found in the function ReadPSDChannelZip in coders/psd.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted psd image file. Se ha encontrado una vulnerabilidad de bucle infinito en ImageMagick 7.0.7-12 Q16 en la función ReadPSDChannelZip en coders/psd.c. Esta vulnerabilidad permite que los atacantes provoquen una denegación de servicio (agotamiento de CPU) mediante un archivo de imagen psd manipulado. It was disc... • http://www.securityfocus.com/bid/102206 • CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') •

CVE-2017-17682 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-17682
14 Dec 2017 — In ImageMagick 7.0.7-12 Q16, a large loop vulnerability was found in the function ExtractPostscript in coders/wpg.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted wpg image file that triggers a ReadWPGImage call. Se ha encontrado una vulnerabilidad de bucle grande en ImageMagick 7.0.7-12 Q16 en la función ExtractPostscript en coders/wpg.c. Esta vulnerabilidad permite que los atacantes provoquen una denegación de servicio (agotamiento de CPU) mediante un archivo de imagen... • http://www.securityfocus.com/bid/102202 • CWE-400: Uncontrolled Resource Consumption •

CVE-2017-16546 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-16546
05 Nov 2017 — The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uninitialized data or invalid memory allocation) or possibly have unspecified other impact via a malformed WPG file. La función ReadWPGImage en coders/wpg.c en ImageMagick 7.0.7-9 no valida correctamente el índice de mapa de colores en una paleta WPG, lo que permite que atacantes remotos provoquen una denegación de... • https://github.com/ImageMagick/ImageMagick/commit/2130bf6f89ded32ef0c88a11694f107c52566c53 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-15281 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-15281
12 Oct 2017 — ReadPSDImage in coders/psd.c in ImageMagick 7.0.7-6 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to "Conditional jump or move depends on uninitialised value(s)." ReadPSDImage en coders/psd.c en ImageMagick 7.0.7-6 permite que atacantes remotos provoquen una denegación de servicio (cierre inesperado de aplicación) o posiblemente produzca otro impacto no especificado mediante un archivo manipulado. Esto está rela... • http://www.securityfocus.com/bid/101276 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-15217 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-15217
10 Oct 2017 — ImageMagick 7.0.7-2 has a memory leak in ReadSGIImage in coders/sgi.c. ImageMagick 7.0.7-2 tiene una fuga de memoria en ReadSGIImage en coders/sgi.c. It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privileges of the user invoking the program. • http://www.securityfocus.com/bid/101231 • CWE-772: Missing Release of Resource after Effective Lifetime •

CVE-2017-15218 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-15218
10 Oct 2017 — ImageMagick 7.0.7-2 has a memory leak in ReadOneJNGImage in coders/png.c. ImageMagick 7.0.7-2 tiene una fuga de memoria en ReadOneJNGImage en coders/png.c. It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privileges of the user invoking the program. • http://www.securityfocus.com/bid/101233 • CWE-772: Missing Release of Resource after Effective Lifetime •

CVE-2017-15032 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-15032
05 Oct 2017 — ImageMagick version 7.0.7-2 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c. ImageMagick 7.0.7-2 tiene una vulnerabilidad de fuga de memoria en ReadYCBCRImage en coders/ycbcr.c. It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privileges of the user invoking the progra... • https://github.com/ImageMagick/ImageMagick/commit/241988ca28139ad970c1d9717c419f41e360ddb0 • CWE-772: Missing Release of Resource after Effective Lifetime •

CVE-2017-15033 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-15033
05 Oct 2017 — ImageMagick version 7.0.7-2 contains a memory leak in ReadYUVImage in coders/yuv.c. ImageMagick 7.0.7-2 tiene una vulnerabilidad de fuga de memoria en ReadYUVImage in coders/yuv.c. It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or possibly execute code with the privileges of the user invoking the program. • https://github.com/ImageMagick/ImageMagick/commit/ef8f40689ac452398026c07da41656a7c87e4683 • CWE-772: Missing Release of Resource after Effective Lifetime •