Description
ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. Attackers can trigger access violations by specifying malformed connected-components definitions via CLI, causing denial of service or potential code execution.
Problem types
Product status
Any version before 7.1.2-19
7.1.2-19 (semver)
Any version before 6.9.13-44
6.9.13-44 (semver)
Credits
ylwango613
References
github.com/...Magick/security/advisories/GHSA-pmpg-6pww-fg6q (GitHub Security Advisory (GHSA-pmpg-6pww-fg6q))
www.vulncheck.com/...image-via-connected-components-artifact (VulnCheck Advisory: ImageMagick - Out-of-bounds Access in ConnectedComponentsImage via connected-components Artifact)