]> rtime.felk.cvut.cz Git - coffee/buildroot.git/commit
imagemagick: add upstream security fix for CVE-2017-7606
authorPeter Korsgaard <peter@korsgaard.com>
Tue, 25 Apr 2017 15:35:54 +0000 (17:35 +0200)
committerPeter Korsgaard <peter@korsgaard.com>
Wed, 26 Apr 2017 07:20:16 +0000 (09:20 +0200)
commit665560856edfcdd18b2053e26bc8a44754dffca2
tree5c6df85c277cbab1c174a5686795c9534601ad71
parent7daae8362be2060527fe1429fa640c325b477d27
imagemagick: add upstream security fix for CVE-2017-7606

This is not yet part of any release.

coders/rle.c in ImageMagick 7.0.5-4 has an "outside the range of
representable values of type unsigned char" undefined behavior issue, which
might allow remote attackers to cause a denial of service (application
crash) or possibly have unspecified other impact via a crafted image.

For more details, see:
https://blogs.gentoo.org/ago/2017/04/02/imagemagick-undefined-behavior-in-codersrle-c/

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/imagemagick/0001-https-github.com-ImageMagick-ImageMagick-issues-415.patch [new file with mode: 0644]