-
Notifications
You must be signed in to change notification settings - Fork 90
Open
Description
ImageMagick version
Operating system
Linux
Operating system, version and so on
Description
CVE-2019-13307
AcquirePixelThreadSet(const Image *images) in magick/statistic.c once caused CVE-2019-13307 and fixed in Commit 91e58d9.
Recurring vulnerabilities
The same issues also advent in
AcquirePixelTLSinmagick/profile.cAcquirePixelTLSinmagick/quantize.cAcquirePixelListTLSinmagick/statistic.c
where use GetMagickResourceLimit directly. Would it make sense to fix them in the same way?
Thank you for spending time reading this issue. Apologies if I missed anything
Steps to Reproduce
Images
Metadata
Metadata
Assignees
Labels
No labels