WriteTIFFImage in coders/tiff.c in ImageMagick 7.0.8-43 Q16 allows attackers to cause a denial-of-service (application crash resulting from a heap-based buffer over-read) via a crafted TIFF image file, related to TIFFRewriteDirectory, TIFFWriteDirectory, TIFFWriteDirectorySec, and TIFFWriteDirectoryTagColormap in tif_dirwrite.c of LibTIFF. NOTE: this occurs because of an incomplete fix for CVE-2019-11597.
{
"unresolved_ranges": [
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:imagemagick:imagemagick:7.0.8-43:q16:*:*:*:*:*:*"
],
"vendor_product": "imagemagick:imagemagick",
"extracted_events": [
{
"last_affected": "7.0.8-43-q16"
},
{
"last_affected": "7.0.8-43-q16"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*",
"cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*"
],
"vendor_product": "opensuse:leap",
"extracted_events": [
{
"last_affected": "15.0"
},
{
"last_affected": "15.1"
}
]
}
]
}