oss-sec mailing list archives

Graphicsmagick: NULL Pointer Dereference in DICOM Decoder (CVE-2017-14994)


From: Terry Chia <terrycwk1994 () gmail com>
Date: Tue, 03 Oct 2017 07:30:06 +0000

A null pointer dereference vulnerability in the GraphicsMagick DICOM image
decoder allows an attacker to cause a denial-of-service condition or other
unspecified impact.

Bug: https://sourceforge.net/p/graphicsmagick/bugs/512/
Writeup: https://nandynarwhals.org/CVE-2017-14994/

Timeline:
30 Sept 2017 - Discovery of the vulnerability.
1 Oct 2017 - Disclosure of vulnerability to the vendor.
1 Oct 2017 - Vulnerability fixed in mercurial commit.
2 Oct 2017 - CVE number requested.
3 Oct 2017 - CVE-2017-14994 assigned.
3 Oct 2017 - Advisory sent to oss-security mailing list.

This issue was discovered by Terry Chia (Ayrx) and Jeremy Heng (@nn_amon).

Current thread: