
CVE-2017-14505 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-14505
17 Sep 2017 — DrawGetStrokeDashArray in wand/drawing-wand.c in ImageMagick 7.0.7-1 mishandles certain NULL arrays, which allows attackers to perform Denial of Service (NULL pointer dereference and application crash in AcquireQuantumMemory within MagickCore/memory.c) by providing a crafted Image File as input. DrawGetStrokeDashArray en wand/drawing-wand.c en ImageMagick 7.0.7-1 no gestiona correctamente algunos arrays NULL, lo que permite a atacantes provocar denegaciones de servicio (desreferencia de puntero NULL y cierr... • http://www.securityfocus.com/bid/100882 • CWE-476: NULL Pointer Dereference •

CVE-2017-14400 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-14400
12 Sep 2017 — In ImageMagick 7.0.7-1 Q16, the PersistPixelCache function in magick/cache.c mishandles the pixel cache nexus, which allows remote attackers to cause a denial of service (NULL pointer dereference in the function GetVirtualPixels in MagickCore/cache.c) via a crafted file. En ImageMagick 7.0.7-1 Q16, la función PersistPixelCache en magick/cache.c no gestiona correctamente el nexo de caché de píxeles, lo que permite que atacantes remotos provoquen una denegación de servicio (desreferencia de puntero NULL en la... • http://www.securityfocus.com/bid/100865 • CWE-476: NULL Pointer Dereference •

CVE-2017-14343 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-14343
12 Sep 2017 — ImageMagick 7.0.6-6 has a memory leak vulnerability in ReadXCFImage in coders/xcf.c via a crafted xcf image file. ImageMagick 7.0.6-6 cuenta con una vulnerabilidad de fuga de memoria en ReadXCFImage en coders/xcf.c mediante un archivo de imagen xcf manipulado. It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or p... • https://github.com/ImageMagick/ImageMagick/issues/649 • CWE-772: Missing Release of Resource after Effective Lifetime •

CVE-2017-14341 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-14341
12 Sep 2017 — ImageMagick 7.0.6-6 has a large loop vulnerability in ReadWPGImage in coders/wpg.c, causing CPU exhaustion via a crafted wpg image file. ImageMagick 7.0.6-6 cuenta con una gran vulnerabilidad de bucle en ReadWPGImage en coders/wpg.c, provocando el agotamiento de la CPU mediante un archivo de imagen wpg manipulado. It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attack... • https://github.com/ImageMagick/ImageMagick/commit/7d63315a64267c565d1f34b9cb523a14616fed24 • CWE-400: Uncontrolled Resource Consumption •

CVE-2017-14342 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-14342
12 Sep 2017 — ImageMagick 7.0.6-6 has a memory exhaustion vulnerability in ReadWPGImage in coders/wpg.c via a crafted wpg image file. ImageMagick 7.0.6-6 cuenta con una vulnerabilidad de agotamiento de memoria en ReadWPGImage en coders/wpg.c mediante un archivo de imagen wpg manipulado. It was discovered that ImageMagick incorrectly handled certain malformed image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of... • https://github.com/ImageMagick/ImageMagick/issues/650 • CWE-400: Uncontrolled Resource Consumption •

CVE-2017-14324
https://notcve.org/view.php?id=CVE-2017-14324
12 Sep 2017 — In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMPCImage in coders/mpc.c, which allows attackers to cause a denial of service via a crafted file. Se ha encontrado una vulnerabilidad de fuga de memoria en ImageMagick 7.0.7-1 Q16 en la función ReadMPCImage en coders/mpc.c. Esta vulnerabilidad permite que los atacantes provoquen una denegación de servicio mediante un archivo manipulado. • http://www.securityfocus.com/bid/100863 • CWE-772: Missing Release of Resource after Effective Lifetime •

CVE-2017-14325 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-14325
12 Sep 2017 — In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function PersistPixelCache in magick/cache.c, which allows attackers to cause a denial of service (memory consumption in ReadMPCImage in coders/mpc.c) via a crafted file. Se ha encontrado una vulnerabilidad de fuga de memoria en ImageMagick 7.0.7-1 Q16 en la función PersistPixelCache en magick/cache.c. Esta vulnerabilidad permite que los atacantes provoquen una denegación de servicio (consumo de memoria en ReadMPCImage en coders/mpc.c)... • http://www.securityfocus.com/bid/100874 • CWE-772: Missing Release of Resource after Effective Lifetime •

CVE-2017-14326 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-14326
12 Sep 2017 — In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service via a crafted file. Se ha encontrado una vulnerabilidad de fuga de memoria en ImageMagick 7.0.7-1 Q16 en la función ReadMATImage en coders/mat.c. Esta vulnerabilidad permite que los atacantes provoquen una denegación de servicio mediante un archivo manipulado. It was discovered that ImageMagick incorrectly handled certain malformed image files. I... • https://github.com/ImageMagick/ImageMagick/issues/740 • CWE-772: Missing Release of Resource after Effective Lifetime •

CVE-2017-14248
https://notcve.org/view.php?id=CVE-2017-14248
11 Sep 2017 — A heap-based buffer over-read in SampleImage() in MagickCore/resize.c in ImageMagick 7.0.6-8 Q16 allows remote attackers to cause a denial of service via a crafted file. Una vulnerabilidad de sobrelectura de búfer basada en memoria dinámica (heap) en SampleImage() en MagickCore/resize.c in ImageMagick 7.0.6-8 Q16 permite que atacantes remotos provoquen una denegación de servicio mediante un archivo manipulado. • https://github.com/ImageMagick/ImageMagick/issues/717 • CWE-125: Out-of-bounds Read •

CVE-2017-14249 – Ubuntu Security Notice USN-3681-1
https://notcve.org/view.php?id=CVE-2017-14249
11 Sep 2017 — ImageMagick 7.0.6-8 Q16 mishandles EOF checks in ReadMPCImage in coders/mpc.c, leading to division by zero in GetPixelCacheTileSize in MagickCore/cache.c, allowing remote attackers to cause a denial of service via a crafted file. ImageMagick 7.0.6-8 Q16 gestiona los chequeos EOF incorrectamente en ReadMPCImage in coders/mpc.c, provocando una división entre cero en GetPixelCacheTileSize in MagickCore/cache.c, permitiendo a los atacantes remotos provocar una denegación de servicio mediante un archivo manipula... • https://github.com/ImageMagick/ImageMagick/issues/708 • CWE-369: Divide By Zero •