In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds read with the MNG CLIP chunk.
[
{
"deprecated": false,
"source": "https://github.com/imagemagick/imagemagick/commit/d072ed6aff835c174e856ce3a428163c0da9e8f4",
"id": "CVE-2017-13139-35ad3697",
"digest": {
"function_hash": "208210774001223053667520481334767139805",
"length": 46883.0
},
"target": {
"function": "ReadOneMNGImage",
"file": "coders/png.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/imagemagick/imagemagick/commit/d072ed6aff835c174e856ce3a428163c0da9e8f4",
"id": "CVE-2017-13139-47ab6e29",
"digest": {
"threshold": 0.9,
"line_hashes": [
"118828374431704979144304713453197291348",
"168294708917582043014934566504230284800",
"142294554047049307418409909111800629614",
"333468367372551722269920330972613167928"
]
},
"target": {
"file": "coders/png.c"
},
"signature_type": "Line",
"signature_version": "v1"
}
]