The cineon parsing component in ImageMagick 7.0.8-26 Q16 allows attackers to cause a denial-of-service (uncontrolled resource consumption) by crafting a Cineon image with an incorrect claimed image size. This occurs because ReadCINImage in coders/cin.c lacks a check for insufficient image data in a file.
{ "vanir_signatures": [ { "signature_type": "Function", "digest": { "length": 14526.0, "function_hash": "75107622566924108883691710748275640944" }, "signature_version": "v1", "source": "https://github.com/imagemagick/imagemagick/commit/e3cdce6fe12193f235b8c0ae5efe6880a25eb957", "id": "CVE-2019-11470-8aca6284", "target": { "file": "coders/cin.c", "function": "ReadCINImage" }, "deprecated": false }, { "signature_type": "Line", "digest": { "line_hashes": [ "64331518748427543874605393599303611404", "311430500361605293787392608047253066271", "145433095778267259839161562382605895900", "197678031840827507874529611307727864571" ], "threshold": 0.9 }, "signature_version": "v1", "source": "https://github.com/imagemagick/imagemagick/commit/e3cdce6fe12193f235b8c0ae5efe6880a25eb957", "id": "CVE-2019-11470-d7672df5", "target": { "file": "coders/cin.c" }, "deprecated": false } ] }