ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read in MagickCore/composite.c in CompositeImage.
[
{
"source": "https://github.com/imagemagick/imagemagick/commit/d29148fae06c01ef215940e084cf41853c117bab",
"digest": {
"line_hashes": [
"2322523866860684260018229908117585092",
"318531461685939415921578562429610859067",
"79807786439770462792633538541839260588",
"51892772308522674402312079150169708637",
"104452184807393472234583898115879005323",
"306919853099184118046933679813562715701",
"107672726896257094298184004162424942273",
"266806071514022134057759369166583326385",
"40302390078139227444251311360367714205",
"145075349470369520160030977321675943876",
"216304108162594901544314274217774032556",
"197769765147974377172045079607214109975",
"184335125942763267093945172255664807784",
"64249425043447701810113058627266562941",
"57988886420917952105176924087195188578"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2019-13303-23328b2f",
"signature_type": "Line",
"target": {
"file": "MagickCore/composite.c"
}
},
{
"source": "https://github.com/imagemagick/imagemagick/commit/d29148fae06c01ef215940e084cf41853c117bab",
"digest": {
"function_hash": "217008371163522161941098242890435051438",
"length": 37695.0
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2019-13303-df810185",
"signature_type": "Function",
"target": {
"function": "CompositeImage",
"file": "MagickCore/composite.c"
}
}
]