SB20171211333 - Reachable Assertion in graphicsmagick (Alpine package)
Published: December 11, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Reachable Assertion (CVE-ID: CVE-2017-14649)
The vulnerability allows a local non-authenticated attacker to perform a denial of service (DoS) attack.
ReadOneJNGImage in coders/png.c in GraphicsMagick version 1.3.26 does not properly validate JNG data, leading to a denial of service (assertion failure in magick/pixel_cache.c, and application crash).
Remediation
Install update from vendor's website.