In ImageMagick before 6.9.8-8 and 7.x before 7.0.5-9, the ReadJP2Image function in coders/jp2.c does not properly validate the channel geometry, leading to a crash.
[
{
"id": "CVE-2017-13145-3c03a189",
"digest": {
"length": 5546.0,
"function_hash": "210812037954842250015360229604252088346"
},
"deprecated": false,
"target": {
"file": "coders/jp2.c",
"function": "ReadJP2Image"
},
"source": "https://github.com/imagemagick/imagemagick/commit/acee073df34aa4d491bf5cb74d3a15fc80f0a3aa",
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2017-13145-b6f97546",
"digest": {
"line_hashes": [
"289544892483923775505698504647299366310",
"150828706856509596378031902790081773088",
"185082364737125337286265695308364243985",
"138996779276094104144166430639441381356"
],
"threshold": 0.9
},
"deprecated": false,
"target": {
"file": "coders/jp2.c"
},
"source": "https://github.com/imagemagick/imagemagick/commit/acee073df34aa4d491bf5cb74d3a15fc80f0a3aa",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2017-13145-d990c8ff",
"digest": {
"line_hashes": [
"181851534386246535276223839725285355550",
"150403642098431120454694618704616516234",
"271398760415669625730399648412166078382",
"2633580211843223113069224974640682329"
],
"threshold": 0.9
},
"deprecated": false,
"target": {
"file": "coders/jp2.c"
},
"source": "https://github.com/imagemagick/imagemagick/commit/f13c6b54a879aaa771ec64b5a066b939e8f8e7f0",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2017-13145-fc3b51fa",
"digest": {
"length": 5852.0,
"function_hash": "39335548675301854673126907520952059124"
},
"deprecated": false,
"target": {
"file": "coders/jp2.c",
"function": "ReadJP2Image"
},
"source": "https://github.com/imagemagick/imagemagick/commit/f13c6b54a879aaa771ec64b5a066b939e8f8e7f0",
"signature_version": "v1",
"signature_type": "Function"
}
]