DrawGetStrokeDashArray in wand/drawing-wand.c in ImageMagick 7.0.7-1 mishandles certain NULL arrays, which allows attackers to perform Denial of Service (NULL pointer dereference and application crash in AcquireQuantumMemory within MagickCore/memory.c) by providing a crafted Image File as input.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Imagemagick | Imagemagick | 7.0.7-1 (including) | 7.0.7-1 (including) |
Imagemagick | Ubuntu | artful | * |
Imagemagick | Ubuntu | bionic | * |
Imagemagick | Ubuntu | devel | * |
Imagemagick | Ubuntu | trusty | * |
Imagemagick | Ubuntu | upstream | * |
Imagemagick | Ubuntu | xenial | * |
Imagemagick | Ubuntu | zesty | * |