In ImageMagick 7.x before 7.0.8-42 and 6.x before 6.9.10-42, there is a use after free vulnerability in the UnmapBlob function that allows an attacker to cause a denial of service by sending a crafted file.
[ { "signature_type": "Function", "id": "CVE-2019-14980-08e53aca", "source": "https://github.com/imagemagick/imagemagick/commit/c5d012a46ae22be9444326aa37969a3f75daa3ba", "signature_version": "v1", "target": { "function": "DetachBlob", "file": "MagickCore/blob.c" }, "digest": { "function_hash": "291010877262477667703302562250498312886", "length": 731.0 }, "deprecated": false }, { "signature_type": "Line", "id": "CVE-2019-14980-357397c4", "source": "https://github.com/imagemagick/imagemagick/commit/c5d012a46ae22be9444326aa37969a3f75daa3ba", "signature_version": "v1", "target": { "file": "MagickCore/blob.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "240547575217823678974276225470322162415", "38728483011723963129938329544653853909", "220465228789161368205841697677186755489", "96289371901039118333275192944269771611" ] }, "deprecated": false } ]
[ { "signature_type": "Line", "id": "CVE-2019-14980-8c189b91", "source": "https://github.com/imagemagick/imagemagick6/commit/614a257295bdcdeda347086761062ac7658b6830", "signature_version": "v1", "target": { "file": "magick/blob.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "240547575217823678974276225470322162415", "38728483011723963129938329544653853909", "220465228789161368205841697677186755489", "96289371901039118333275192944269771611" ] }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2019-14980-bac24320", "source": "https://github.com/imagemagick/imagemagick6/commit/614a257295bdcdeda347086761062ac7658b6830", "signature_version": "v1", "target": { "function": "DetachBlob", "file": "magick/blob.c" }, "digest": { "function_hash": "137616152220278181952427592358977441460", "length": 705.0 }, "deprecated": false } ]