In ImageMagick 7.0.8-36 Q16, there is a memory leak in the function
SVGKeyValuePairs of coders/svg.c, which allows an attacker to cause a
denial of service via a crafted image file. (CVE-2019-10649)
In ImageMagick 7.0.8-36 Q16, there is a heap-based buffer over-read in the
function WriteTIFFImage of coders/tiff.c, which allows an attacker to
cause a denial of service or information disclosure via a crafted image
file. (CVE-2019-10650)
- https://bugs.mageia.org/show_bug.cgi?id=24614
- https://github.com/ImageMagick/Website/blob/main/ChangeLog.md
- https://www.cve.org/CVERecord?id=CVE-2019-10649
- https://www.cve.org/CVERecord?id=CVE-2019-10650
- 6/core/imagemagick-6.9.10.36-1.mga6
Get the latest Linux and open source security news straight to your inbox.