CVE-2017-11166

Priority
Low
Description
The ReadXWDImage function in coders\xwd.c in ImageMagick 7.0.5-6 has a
memory leak vulnerability that can cause memory exhaustion via a crafted
length (number of color-map entries) field in the header of an XWD file.
References
Bugs
Notes
 mdeslaur> fix by 0034-2-2-CVE-2017-8352.patch
 mdeslaur> as of 2017-07-21, doesn't appear fixed in jessie
Package
Upstream:needs-triage
Ubuntu 17.10 (Artful Aardvark):not-affected (8:6.9.7.4+dfsg-12ubuntu1)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):needed
Ubuntu 16.04 LTS (Xenial Xerus):needed
Ubuntu 17.04 (Zesty Zapus):not-affected (8:6.9.7.4+dfsg-3ubuntu1.1)
Patches:
Upstream:https://github.com/ImageMagick/ImageMagick/commit/31b842a218225cd7feddf65cbccf9d783c6cb526
Upstream:https://github.com/ImageMagick/ImageMagick/commit/5964475e21e7e3bdd27835b71aa17d1678c21d7c (im6)
More Information

Updated: 2017-10-23 12:28:58 UTC (commit 13562)