Package: imagemagick
Version: 8:6.7.7.10-5
Severity: grave
Tags: patch security
X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org


The DrawImage function in MagickCore/draw.c in ImageMagick before
6.9.4-0 and 7.x before 7.0.1-2 makes an incorrect function call in
attempting to locate the next token, which allows remote attackers to
cause a denial of service (buffer overflow and application crash) or
possibly have unspecified other impact via a crafted file.

Reply via email to