coders/mpc.c in ImageMagick before 7.0.6-1 does not enable seekable streams and thus cannot validate blob sizes, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an image received from stdin.
[
{
"digest": {
"length": 574.0,
"function_hash": "50210246413655033184503255044832953378"
},
"target": {
"file": "coders/mpc.c",
"function": "RegisterMPCImage"
},
"source": "https://github.com/imagemagick/imagemagick/commit/b007dd3a048097d8f58949297f5b434612e1e1a3",
"id": "CVE-2017-11449-708197e3",
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function"
},
{
"digest": {
"line_hashes": [
"289790261950978927062890139494971400293",
"42955579105180743444049797488509417119",
"40782650941201800503312105572279006367",
"50560069848468478718187569227748359994",
"185946262822082868847179569053753178537",
"167169125954746693327943733003800258737",
"279310443560654285899413573822525098439",
"41265843592503498045219320689666491393"
],
"threshold": 0.9
},
"target": {
"file": "coders/mpc.c"
},
"source": "https://github.com/imagemagick/imagemagick/commit/b007dd3a048097d8f58949297f5b434612e1e1a3",
"id": "CVE-2017-11449-da0d90ab",
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line"
}
]