In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.
[
{
"source": "https://github.com/imagemagick/imagemagick/commit/db0add932fb850d762b02604ca3053b7d7ab6deb",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"293618921234006187725026705153267768408",
"219143665669723635930644710924043484224",
"170557331076595812404947877217045034650",
"96903361799435717810353801926990434717",
"310580233459027267181364493513210713452",
"172043174085921814705713042194620648075",
"339103991722258511311485492361405518590",
"136276267307880617912353831816070723228",
"5799514899510382603266263518417502069",
"232385043645597361895693391864307687072",
"186038132249756181061372186195446953558",
"340206235807699397960135583932195821887",
"326877051604193313666551318498397581865",
"246186099544855009949670345724067477557",
"78219939539375403463584502218923075938"
]
},
"signature_type": "Line",
"id": "CVE-2018-20467-05218939",
"signature_version": "v1",
"target": {
"file": "coders/bmp.c"
}
},
{
"source": "https://github.com/imagemagick/imagemagick/commit/db0add932fb850d762b02604ca3053b7d7ab6deb",
"deprecated": false,
"digest": {
"function_hash": "18072874593179590851956265762794069767",
"length": 23797.0
},
"signature_type": "Function",
"id": "CVE-2018-20467-5bcc1c50",
"signature_version": "v1",
"target": {
"function": "ReadBMPImage",
"file": "coders/bmp.c"
}
}
]