Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Viennaddo

Researcher fromSourceBrella Inc.
#19155of 53,633
14Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2017-4126
7.5
2017-09-25
Imagemagick · Imagemagick · CVE-2017-14739
**Name of the Vulnerable Software and Affected Versions** ImageMagick version 7.0.7-4 **Description** The issue is related to the AcquireResampleFilterThreadSet function in the magick/resample-private.h component of ImageMagick, which is associated with a null pointer dereference. This can be exploited by a remote attacker to cause a denial of service, leading to an application crash due to failed memory allocation in the DistortImage function in MagickCore/distort.c. **Recommendations** For ImageMagick version 7.0.7-4, consider disabling the AcquireResampleFilterThreadSet function as a temporary workaround until a patch is available to prevent potential denial of service attacks.
PT-2017-4107
6.5
2017-09-22
Imagemagick · Imagemagick · CVE-2017-1000445
**Name of the Vulnerable Software and Affected Versions** ImageMagick versions 7.0.7-1 and earlier **Description** The issue is related to a null pointer dereference in the MagickCore component, which could lead to a denial of service. This allows a remote attacker to exploit the vulnerability and cause a service disruption. **Recommendations** For ImageMagick versions 7.0.7-1 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.