There is a missing check for length in the functions ReadDCMImage of coders/dcm.c and ReadPICTImage of coders/pict.c in ImageMagick 7.0.8-11, which allows remote attackers to cause a denial of service via a crafted image.
{ "vanir_signatures": [ { "digest": { "function_hash": "216344764721089435425809697740891896637", "length": 27685.0 }, "signature_type": "Function", "source": "https://github.com/imagemagick/imagemagick/commit/16916c8979c32765c542e216b31cee2671b7afe7", "target": { "file": "coders/dcm.c", "function": "ReadDCMImage" }, "signature_version": "v1", "deprecated": false, "id": "CVE-2018-16644-151fd89c" }, { "digest": { "threshold": 0.9, "line_hashes": [ "282532765129590003694466301263899582732", "28575460015977794251610399265088909547", "217428959336495974744478309101155832700", "91983129253813061800588339833023037686", "37483863734739795505907049196586496695", "55601521399508558922552616954761080836", "222108361130992487661678340231729585411", "45267993873415893655198510725235563523", "102861351974321239463654041454065620485", "230821806491836518422991815357813878619", "315261130184466075111194072546714799232", "12916301218640047330922904718861499059", "111257503344439224121001840319533509963", "112100833970445811542922415959476143205", "335062944483755306039754672033561531573", "234530208679493171825701544464978158847", "161688064976702416054686415126221409005", "327824439739758784225876323002098557415", "335062944483755306039754672033561531573", "234530208679493171825701544464978158847", "171282357923086536838539842662062027402", "309104253251563304176823317934882032628", "235383814969330485333753363194890716155", "302836472018851990782674805463554345027", "205389503708690087342682217076531245574", "335375314649863373442602802043992734059", "141330677716083687253799837651004802193", "241603333444238604478965794023226202297", "112957699429535062050344174691128768070", "43205081347224939791448762780325004508", "295765431739850849530213121397589924738", "66636134402260882666810542486448256827", "30716425759604132704142046334492865436", "247883289141306761883263428253879634356", "183025716017305886973560224867389431433", "34483684178405649285224538896685681856" ] }, "signature_type": "Line", "source": "https://github.com/imagemagick/imagemagick/commit/afa878a689870c28b6994ecf3bb8dbfb2b76d135", "target": { "file": "coders/pict.c" }, "signature_version": "v1", "deprecated": false, "id": "CVE-2018-16644-2dcbff7c" }, { "digest": { "threshold": 0.9, "line_hashes": [ "196241113006705054470804958438605567720", "263961331765887318856875363007917119891", "126978134994261841828292926358304326723", "156422671895451978979885945500638271676" ] }, "signature_type": "Line", "source": "https://github.com/imagemagick/imagemagick/commit/16916c8979c32765c542e216b31cee2671b7afe7", "target": { "file": "coders/dcm.c" }, "signature_version": "v1", "deprecated": false, "id": "CVE-2018-16644-3eded309" }, { "digest": { "function_hash": "325129785612070796534989567550768104245", "length": 15934.0 }, "signature_type": "Function", "source": "https://github.com/imagemagick/imagemagick/commit/afa878a689870c28b6994ecf3bb8dbfb2b76d135", "target": { "file": "coders/pict.c", "function": "ReadPICTImage" }, "signature_version": "v1", "deprecated": false, "id": "CVE-2018-16644-e82b9979" } ] }