The ReadRLEImage function in codersrle.c in ImageMagick 7.0.6-1 has a large loop vulnerability via a crafted rle file that triggers a huge number_pixels value.
The product performs an iteration or loop without sufficiently limiting the number of times that the loop is executed.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Imagemagick | Imagemagick | 7.0.6-1 (including) | 7.0.6-1 (including) |
Imagemagick | Ubuntu | trusty | * |
Imagemagick | Ubuntu | upstream | * |
Imagemagick | Ubuntu | xenial | * |
Imagemagick | Ubuntu | yakkety | * |
Imagemagick | Ubuntu | zesty | * |