Candidate: CVE-2017-13658 PublicDate: 2017-08-24 06:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13658 Description: In ImageMagick before 6.9.9-3 and 7.x before 7.0.6-3, there is a missing NULL check in the ReadMATImage function in coders/mat.c, leading to a denial of service (assertion failure and application exit) in the DestroyImageInfo function in MagickCore/image.c. Ubuntu-Description: Notes: mdeslaur> 0107-assertion-failed-in-DestroyImageInfo-due-to-mat-code.patch in unstable mdeslaur> 0299-CVE-2017-13658-Fix-missing-NULL-check-in-ReadMATImage.patch in wheezy mdeslaur> xenial and trusty don't look vulnerable Bugs: https://github.com/ImageMagick/ImageMagick/issues/598 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=870019 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_imagemagick: upstream: https://github.com/ImageMagick/ImageMagick/commit/e5c063a1007506ba69e97a35effcdef944421c89 upstream_imagemagick: released (8:6.9.7.4+dfsg-14) precise/esm_imagemagick: DNE trusty_imagemagick: not-affected (code not present) trusty/esm_imagemagick: DNE (trusty was not-affected [code not present]) vivid/ubuntu-core_imagemagick: DNE xenial_imagemagick: not-affected (code not present) esm-infra/xenial_imagemagick: not-affected (code not present) zesty_imagemagick: ignored (reached end-of-life) artful_imagemagick: not-affected (8:6.9.7.4+dfsg-16ubuntu2) bionic_imagemagick: not-affected (8:6.9.7.4+dfsg-16ubuntu2) devel_imagemagick: not-affected (8:6.9.7.4+dfsg-16ubuntu2)