oss-sec mailing list archives

Asking for CVE for imagemagick


From: Bastien ROUCARIES <roucaries.bastien () gmail com>
Date: Fri, 7 Nov 2014 20:41:00 +0100

Hi,

I am asking for two CVE for imagemagick (two DOS):
- Converting some specially crafted jpeg could lead to a dos (see
http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26456)
- Converting some dcm file could lead to crash then DOS:
Fix last value in dicom_info and added missing != NULL check.

Fix a buffer overflow in dcm reader by checking the dcm file.
This problem was discovered by fuzzing some dcm file.

Thanks

Bastien


Current thread: