In ImageMagick 7.0.5-7 Q16, an assertion failure was found in the function SetPixelChannelAttributes, which allows attackers to cause a denial of service via a crafted file.
[
{
"signature_version": "v1",
"source": "https://github.com/imagemagick/imagemagick/commit/7fd419441bc7103398e313558171d342c6315f44",
"deprecated": false,
"id": "CVE-2017-9499-4980f020",
"signature_type": "Function",
"digest": {
"function_hash": "44583101693599326754483077164930684048",
"length": 16006.0
},
"target": {
"function": "ReadMPCImage",
"file": "coders/mpc.c"
}
},
{
"signature_version": "v1",
"source": "https://github.com/imagemagick/imagemagick/commit/7fd419441bc7103398e313558171d342c6315f44",
"deprecated": false,
"id": "CVE-2017-9499-80bf895c",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"102848933437140452865823474122891616215",
"262814841214861245278774592368400683306",
"38299471795231826873674129078644465333",
"214345926839899270898155115862566665405"
]
},
"target": {
"file": "coders/mpc.c"
}
}
]