WriteTIFFImage in coders/tiff.c in ImageMagick 7.0.8-43 Q16 allows attackers to cause a denial-of-service (application crash resulting from a heap-based buffer over-read) via a crafted TIFF image file, related to TIFFRewriteDirectory, TIFFWriteDirectory, TIFFWriteDirectorySec, and TIFFWriteDirectoryTagColormap in tif_dirwrite.c of LibTIFF. NOTE: this occurs because of an incomplete fix for CVE-2019-11597.
{ "vanir_signatures": [ { "digest": { "length": 22195.0, "function_hash": "215563055834514169536177540504944461963" }, "signature_type": "Function", "signature_version": "v1", "source": "https://github.com/imagemagick/imagemagick6/commit/3c53413eb544cc567309b4c86485eae43e956112", "deprecated": false, "target": { "file": "coders/tiff.c", "function": "WriteTIFFImage" }, "id": "CVE-2019-15141-78963c98" }, { "digest": { "threshold": 0.9, "line_hashes": [ "229806444073452828964247372215557024112", "266785009780016695435268592834636824513", "140339915890535396982942881607401085185", "3715853625551547673875598232730654752", "280616622160105672154578357525564650798", "280768714420765778141026955921511780202", "84054414522524673470275503801569773399", "271744368221907684365587794775045299903", "97826747127678175374869272971204208610", "48081907844134289868645538181809869432", "114919572739648422175450077841308440381", "103897191576738784706701875685820783883", "135792897195423023304033942187914599692" ] }, "signature_type": "Line", "signature_version": "v1", "source": "https://github.com/imagemagick/imagemagick6/commit/3c53413eb544cc567309b4c86485eae43e956112", "deprecated": false, "target": { "file": "coders/tiff.c" }, "id": "CVE-2019-15141-d768095c" } ] }