Menu

#565 ImageMagick CVE-2017-18272 applies to GraphicsMagick

v1.0_(example)
closed-fixed
None
5
2018-06-20
2018-05-23
Petr Gajdos
No

GraphicsMagick seem to share the issue, testcase and patch for CVE-2017-18272:
https://github.com/ImageMagick/ImageMagick/commit/7523250e2664028aa1d8f02d2d7ae49c769a851e
Attaching a patch against 15658:ebd3eb090848.

BEFORE

$ gm convert cpu-exhaustion-ReadMIFFImage /dev/null
[hangs]

AFTER

$ gm convert cpu-exhaustion-ReadMIFFImage /dev/null
gm convert: Unexpected end-of-file (cpu-exhaustion-ReadMIFFImage).
$
1 Attachments

Discussion

  • Bob Friesenhahn

    Bob Friesenhahn - 2018-06-10
    • status: open --> closed-fixed
    • assigned_to: Bob Friesenhahn
     
  • Bob Friesenhahn

    Bob Friesenhahn - 2018-06-10

    This fix is applied as Mercurial changeset 15701:23f53da8b9d3. Thanks for the report!

     
  • Petr Gajdos

    Petr Gajdos - 2018-06-20

    Thank you!

     

Log in to post a comment.

MongoDB Logo MongoDB