Launch Week Day 1: Announcing Security Design Review
LOW 3.3 NuGet

ImageMagick: Heap-based Buffer Overflow in GetPixelIndex due to metadata-cache desynchronization

GHSA-gq5v-qf8q-fp77

Published ยท Modified

Description

OpenPixelCache updates image channel metadata before attempting pixel cache memory allocation. When both memory and disk allocation fail a heap-buffer-overflow read in occurs in any writer that calls GetPixelIndex.

Ready to move

Start Securing

Free, no credit card | First findings in minutes