CVE-2017-14739

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
26/09/2017
Last modified:
20/04/2025

Description

The AcquireResampleFilterThreadSet function in magick/resample-private.h in ImageMagick 7.0.7-4 mishandles failed memory allocation, which allows remote attackers to cause a denial of service (NULL Pointer Dereference in DistortImage in MagickCore/distort.c, and application crash) via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:imagemagick:imagemagick:7.0.7-4:*:*:*:*:*:*:*