Bug 222621

Summary: security/vuxml: Security Vulnerability in ImageMagick (CVE-2017-14741)
Product: Ports & Packages Reporter: VK <vlad-fbsd>
Component: Individual Port(s)Assignee: Ports Security Team <ports-secteam>
Status: Closed FIXED    
Severity: Affects Some People CC: kwm, swills
Priority: --- Keywords: patch, security
Version: LatestFlags: bugzilla: maintainer-feedback? (ports-secteam)
Hardware: Any   
OS: Any   
URL: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14741
Attachments:
Description Flags
Document CVE-2017-14741 none

Description VK 2017-09-26 11:48:59 UTC
Created attachment 186737 [details]
Document CVE-2017-14741

The ReadCAPTIONImage function in coders/caption.c in ImageMagick 7.0.7-3 allows remote attackers to cause a denial of service (infinite loop) via a crafted font file.

However, since upstream contains a commit for the ImageMagick-6 branch (which hasn't been tagged for update) as well, I'm adding it too.
Comment 1 Steve Wills freebsd_committer freebsd_triage 2017-09-27 15:42:32 UTC
Committed in r450758. Thanks!