Launch Week Day 1: Announcing Security Design Review
LOW 3.7 NuGet

ImageMagick: Malicious PCD files trigger 1‑byte heap Out-of-bounds Read and DoS

GHSA-wgxp-q8xq-wpp9

Published · Modified

Description

The PCD coder’s DecodeImage loop allows a crafted PCD file to trigger a 1‑byte heap out-of-bounds read when decoding an image (Denial of service) and potential disclosure of adjacent heap byte.

Ready to move

Start Securing

Free, no credit card | First findings in minutes