VDB
KO
MEDIUM 5.3

GHSA-g5mf-wqq5-vwg6

ImageMagick: Policy Bypass in MNG coder could

Details

Because of a missing check in the MNG coder it would be possible to read more images than the list limit policy would allow resulting in excessive resource use.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet / Magick.NET-Q16-AnyCPU
Introduced in: 0 Fixed in: 14.13.1
Fix dotnet add package Magick.NET-Q16-AnyCPU --version 14.13.1
NuGet / Magick.NET-Q16-HDRI-AnyCPU
Introduced in: 0 Fixed in: 14.13.1
Fix dotnet add package Magick.NET-Q16-HDRI-AnyCPU --version 14.13.1
NuGet / Magick.NET-Q16-HDRI-OpenMP-arm64
Introduced in: 0 Fixed in: 14.13.1
Fix dotnet add package Magick.NET-Q16-HDRI-OpenMP-arm64 --version 14.13.1
NuGet / Magick.NET-Q16-HDRI-OpenMP-x64
Introduced in: 0 Fixed in: 14.13.1
Fix dotnet add package Magick.NET-Q16-HDRI-OpenMP-x64 --version 14.13.1
NuGet / Magick.NET-Q16-HDRI-arm64
Introduced in: 0 Fixed in: 14.13.1
Fix dotnet add package Magick.NET-Q16-HDRI-arm64 --version 14.13.1
NuGet / Magick.NET-Q16-HDRI-x64
Introduced in: 0 Fixed in: 14.13.1
Fix dotnet add package Magick.NET-Q16-HDRI-x64 --version 14.13.1
NuGet / Magick.NET-Q16-HDRI-x86
Introduced in: 0 Fixed in: 14.13.1
Fix dotnet add package Magick.NET-Q16-HDRI-x86 --version 14.13.1
NuGet / Magick.NET-Q16-OpenMP-arm64
Introduced in: 0 Fixed in: 14.13.1
Fix dotnet add package Magick.NET-Q16-OpenMP-arm64 --version 14.13.1
NuGet / Magick.NET-Q16-OpenMP-x64
Introduced in: 0 Fixed in: 14.13.1
Fix dotnet add package Magick.NET-Q16-OpenMP-x64 --version 14.13.1
NuGet / Magick.NET-Q16-arm64
Introduced in: 0 Fixed in: 14.13.1
Fix dotnet add package Magick.NET-Q16-arm64 --version 14.13.1
NuGet / Magick.NET-Q16-x64
Introduced in: 0 Fixed in: 14.13.1
Fix dotnet add package Magick.NET-Q16-x64 --version 14.13.1
NuGet / Magick.NET-Q16-x86
Introduced in: 0 Fixed in: 14.13.1
Fix dotnet add package Magick.NET-Q16-x86 --version 14.13.1
NuGet / Magick.NET-Q8-AnyCPU
Introduced in: 0 Fixed in: 14.13.1
Fix dotnet add package Magick.NET-Q8-AnyCPU --version 14.13.1
NuGet / Magick.NET-Q8-OpenMP-arm64
Introduced in: 0 Fixed in: 14.13.1
Fix dotnet add package Magick.NET-Q8-OpenMP-arm64 --version 14.13.1
NuGet / Magick.NET-Q8-OpenMP-x64
Introduced in: 0 Fixed in: 14.13.1
Fix dotnet add package Magick.NET-Q8-OpenMP-x64 --version 14.13.1
NuGet / Magick.NET-Q8-arm64
Introduced in: 0 Fixed in: 14.13.1
Fix dotnet add package Magick.NET-Q8-arm64 --version 14.13.1
NuGet / Magick.NET-Q8-x64
Introduced in: 0 Fixed in: 14.13.1
Fix dotnet add package Magick.NET-Q8-x64 --version 14.13.1
NuGet / Magick.NET-Q8-x86
Introduced in: 0 Fixed in: 14.13.1
Fix dotnet add package Magick.NET-Q8-x86 --version 14.13.1

References