Heap-based buffer overflow in the PushQuantumPixel function in ImageMagick before 6.9.7-3 and 7.x before 7.0.4-3 allows remote attackers to cause a denial of service (application crash) via a crafted TIFF file.
{ "vanir_signatures": [ { "digest": { "length": 23249.0, "function_hash": "64327381050776383374483875130080754838" }, "target": { "function": "ReadTIFFImage", "file": "coders/tiff.c" }, "signature_version": "v1", "signature_type": "Function", "id": "CVE-2017-5508-8c565714", "source": "https://github.com/imagemagick/imagemagick/commit/c073a7712d82476b5fbee74856c46b88af9c3175", "deprecated": false }, { "digest": { "line_hashes": [ "339783385470963704518081453680787509394", "170187431441979370390447072169831908618", "64693590836930932883851585134442121071", "90088925699755770610197656072186626388", "31699036766545690104974140604545672305" ], "threshold": 0.9 }, "target": { "file": "coders/tiff.c" }, "signature_version": "v1", "signature_type": "Line", "id": "CVE-2017-5508-f2ebedec", "source": "https://github.com/imagemagick/imagemagick/commit/c073a7712d82476b5fbee74856c46b88af9c3175", "deprecated": false } ] }