DrawGetStrokeDashArray in wand/drawing-wand.c in ImageMagick 7.0.7-1 mishandles certain NULL arrays, which allows attackers to perform Denial of Service (NULL pointer dereference and application crash in AcquireQuantumMemory within MagickCore/memory.c) by providing a crafted Image File as input.
References
Configurations
Information
Published : 2017-09-17 12:29
Updated : 2020-09-07 17:15
NVD link : CVE-2017-14505
Mitre link : CVE-2017-14505
JSON object : View
CWE
CWE-476
NULL Pointer Dereference
Products Affected
imagemagick
- imagemagick