mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-09 19:17:37 +02:00
800 B
800 B
CVE-2017-11449
Description
coders/mpc.c in ImageMagick before 7.0.6-1 does not enable seekable streams and thus cannot validate blob sizes, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an image received from stdin.
POC
Reference
- https://github.com/ImageMagick/ImageMagick/issues/556
- https://github.com/ImageMagick/ImageMagick/issues/556
Github
No PoCs found on GitHub currently.