In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the WriteBlob function in MagickCore/blob.c because of missing checks in the ReadOneJNGImage function in coders/png.c.
[
{
"id": "CVE-2017-9142-244169d5",
"signature_type": "Function",
"target": {
"function": "ReadOneJNGImage",
"file": "coders/png.c"
},
"source": "https://github.com/imagemagick/imagemagick/commit/f0232a2a45dfd003c1faf6079497895df3ab0ee1",
"digest": {
"length": 13944.0,
"function_hash": "10685912637953292967486052057510858512"
},
"signature_version": "v1",
"deprecated": false
},
{
"id": "CVE-2017-9142-f5812a24",
"signature_type": "Line",
"target": {
"file": "coders/png.c"
},
"source": "https://github.com/imagemagick/imagemagick/commit/f0232a2a45dfd003c1faf6079497895df3ab0ee1",
"digest": {
"line_hashes": [
"55354417517607064168098092458754790588",
"164047965787487540201063060851091045772",
"303364345114828104705308682115659084046",
"179387021110365750541732828470146625576",
"294720302399277623319787137900643143319",
"24882106847455866198505122312345103341"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false
}
]