PublicDateAtUSN: 2017-04-30 Candidate: CVE-2017-8350 PublicDate: 2017-04-30 17:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8350 https://github.com/ImageMagick/ImageMagick/issues/447 https://ubuntu.com/security/notices/USN-3302-1 Description: In ImageMagick 7.0.5-5, the ReadJNGImage function in png.c allows attackers to cause a denial of service (memory leak) via a crafted file. Ubuntu-Description: Notes: mdeslaur> This is 0201-1-3-CVE-2017-8350-Fixed-more-memory-leaks.patch and mdeslaur> 0202-3-3-CVE-2017-8350-Fixed-various-leaks-in-ReadOneJNGI.patch Bugs: Priority: negligible Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_imagemagick: upstream_imagemagick: needs-triage precise_imagemagick: ignored (reached end-of-life) precise/esm_imagemagick: DNE (precise was needs-triage) trusty_imagemagick: released (8:6.7.7.10-6ubuntu3.7) trusty/esm_imagemagick: DNE (trusty was released [8:6.7.7.10-6ubuntu3.7]) vivid/stable-phone-overlay_imagemagick: DNE vivid/ubuntu-core_imagemagick: DNE xenial_imagemagick: released (8:6.8.9.9-7ubuntu5.7) esm-infra/xenial_imagemagick: released (8:6.8.9.9-7ubuntu5.7) yakkety_imagemagick: released (8:6.8.9.9-7ubuntu8.6) zesty_imagemagick: released (8:6.9.7.4+dfsg-3ubuntu1.1) devel_imagemagick: released (8:6.9.7.4+dfsg-9ubuntu1)