DrawGetStrokeDashArray in wand/drawing-wand.c in ImageMagick 7.0.7-1 mishandles certain NULL arrays, which allows attackers to perform Denial of Service (NULL pointer dereference and application crash in AcquireQuantumMemory within MagickCore/memory.c) by providing a crafted Image File as input.
References
Configurations
History
No history.
Information
Published : 2017-09-17 19:29
Updated : 2020-09-08 00:15
NVD link : CVE-2017-14505
Mitre link : CVE-2017-14505
CVE.ORG link : CVE-2017-14505
JSON object : View
Products Affected
imagemagick
- imagemagick
CWE
CWE-476
NULL Pointer Dereference