Daily Archives: October 7, 2016

imagemagick: memory allocate failure in AcquireQuantumPixels (quantum.c)

Description: imagemagick is a software suite to create, edit, compose, or convert bitmap images. A fuzzing with the upstream security policy enabled revealed a memory allocate failure. The complete ASan output: # identify $FILE ==25084==WARNING: AddressSanitizer failed to allocate 0x46bf39483ac … Continue reading

Posted in advisories, security | Leave a comment

imagemagick: heap-based buffer overflow in IsPixelMonochrome (pixel-accessor.h)

Description: imagemagick is a software suite to create, edit, compose, or convert bitmap images. A fuzzing with the upstream security policy enabled revealed a buffer overflow read. The complete ASan output: # identify $FILE ==13198==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x61400000fbc0 … Continue reading

Posted in advisories, security | Leave a comment