There are several memory leaks in the MIFF coder in ...
Moderate severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Dec 8, 2020
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jan 29, 2023
There are several memory leaks in the MIFF coder in /coders/miff.c due to improper image depth values, which can be triggered by a specially crafted input file. These leaks could potentially lead to an impact to application availability or cause a denial of service. It was originally reported that the issues were in
AcquireMagickMemory()
because that is where LeakSanitizer detected the leaks, but the patch resolves issues in the MIFF coder, which incorrectly handles data being passed toAcquireMagickMemory()
. This flaw affects ImageMagick versions prior to 7.0.9-0.References