WriteTIFFImage in coders/tiff.c in ImageMagick 7.0.8-43 Q16 allows attackers to cause a denial-of-service (application crash resulting from a heap-based buffer over-read) via a crafted TIFF image file, related to TIFFRewriteDirectory, TIFFWriteDirectory, TIFFWriteDirectorySec, and TIFFWriteDirectoryTagColormap in tif_dirwrite.c of LibTIFF. NOTE: this occurs because of an incomplete fix for CVE-2019-11597.
[
{
"digest": {
"function_hash": "215563055834514169536177540504944461963",
"length": 22195.0
},
"source": "https://github.com/imagemagick/imagemagick6/commit/3c53413eb544cc567309b4c86485eae43e956112",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "coders/tiff.c",
"function": "WriteTIFFImage"
},
"id": "CVE-2019-15141-78963c98",
"signature_type": "Function"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"229806444073452828964247372215557024112",
"266785009780016695435268592834636824513",
"140339915890535396982942881607401085185",
"3715853625551547673875598232730654752",
"280616622160105672154578357525564650798",
"280768714420765778141026955921511780202",
"84054414522524673470275503801569773399",
"271744368221907684365587794775045299903",
"97826747127678175374869272971204208610",
"48081907844134289868645538181809869432",
"114919572739648422175450077841308440381",
"103897191576738784706701875685820783883",
"135792897195423023304033942187914599692"
]
},
"source": "https://github.com/imagemagick/imagemagick6/commit/3c53413eb544cc567309b4c86485eae43e956112",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "coders/tiff.c"
},
"id": "CVE-2019-15141-d768095c",
"signature_type": "Line"
}
]