Description
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huffman-coded data from PCD (Photo CD) files. The decoder contains an function that has an incorrect initialization that could cause an out of bounds read. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Problem types
CWE-122: Heap-based Buffer Overflow
Product status
< 6.9.13-40
References
github.com/...Magick/security/advisories/GHSA-wrhr-rf8j-r842