ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows.
[
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"105457957266992163600397784467911012864",
"113502714572540751338282177106943565411",
"131352766856713130247136133288259088806",
"208351102372676431955061896583642085284",
"221470689196922184248347942481580364275",
"167966186430876343356799793379607260243",
"180510603992647546579305887327561640057",
"84568744422222018656790852240493698893",
"290008347618620899133113066805843581428",
"205213132471849264631113514132271626040",
"157068344437711510051371991859456164162",
"187064918045232381902598238192910610583",
"242562180137500128837313806753247771133",
"279878274855968029922299685470369274421"
]
},
"target": {
"file": "MagickCore/statistic.c"
},
"source": "https://github.com/imagemagick/imagemagick/commit/025e77fcb2f45b21689931ba3bf74eac153afa48",
"id": "CVE-2019-13307-eb1d490d",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Function",
"digest": {
"function_hash": "287821828239848222157026039943782817642",
"length": 871.0
},
"target": {
"file": "MagickCore/statistic.c",
"function": "AcquirePixelThreadSet"
},
"source": "https://github.com/imagemagick/imagemagick/commit/025e77fcb2f45b21689931ba3bf74eac153afa48",
"id": "CVE-2019-13307-ee575a47",
"deprecated": false,
"signature_version": "v1"
}
]
[
{
"signature_type": "Function",
"digest": {
"function_hash": "227183710927715851385752933276828651301",
"length": 780.0
},
"target": {
"file": "magick/statistic.c",
"function": "AcquirePixelThreadSet"
},
"source": "https://github.com/imagemagick/imagemagick6/commit/91e58d967a92250439ede038ccfb0913a81e59fe",
"id": "CVE-2019-13307-e480b35e",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"57063751727762952091049005679334265917",
"113502714572540751338282177106943565411",
"279342851013028598906720271822326764308",
"333090040705412081734891161475359584319",
"166591158397969553092131162797869008206",
"151124482436635167576724954410633580608",
"326394045144129747231328685586249213587",
"260290302060196939174424994031801759807",
"156181899458264737788216578542038925836",
"205213132471849264631113514132271626040",
"157068344437711510051371991859456164162",
"187064918045232381902598238192910610583",
"78134888531581652395640578558054048094",
"144916994949891328611276888500568223318"
]
},
"target": {
"file": "magick/statistic.c"
},
"source": "https://github.com/imagemagick/imagemagick6/commit/91e58d967a92250439ede038ccfb0913a81e59fe",
"id": "CVE-2019-13307-edb17fcd",
"deprecated": false,
"signature_version": "v1"
}
]