ReadXWDImage in coders/xwd.c in the XWD image parsing component of ImageMagick 7.0.8-41 Q16 allows attackers to cause a denial-of-service (divide-by-zero error) by crafting an XWD image file in which the header indicates neither LSB first nor MSB first.
{ "vanir_signatures": [ { "source": "https://github.com/imagemagick/imagemagick6/commit/f663dfb8431c97d95682a2b533cca1c8233d21b4", "deprecated": false, "signature_version": "v1", "digest": { "line_hashes": [ "262297152321783040730359791878549613721", "244207029567887000359546043118606780371", "41546457161766143982003651069591802118", "205709512898460440472673759115210283577" ], "threshold": 0.9 }, "signature_type": "Line", "id": "CVE-2019-11472-13f51dea", "target": { "file": "coders/xwd.c" } }, { "source": "https://github.com/imagemagick/imagemagick6/commit/f663dfb8431c97d95682a2b533cca1c8233d21b4", "deprecated": false, "signature_version": "v1", "digest": { "function_hash": "33797782550404342059440183549741275083", "length": 10984.0 }, "signature_type": "Function", "id": "CVE-2019-11472-9712b51a", "target": { "function": "ReadXWDImage", "file": "coders/xwd.c" } } ] }