GHSA-xxw5-m53x-j38c
ImageMagick has heap use-after-free in the MSL encoder
Details
A heap-use-after-free vulnerability exists in the MSL encoder, where a cloned image is destroyed twice. The MSL coder does not support writing MSL so the write capability has been removed.
``` SUMMARY: AddressSanitizer: heap-use-after-free MagickCore/image.c:1195 in DestroyImage Shadow bytes around the buggy address: 0x0a4e80007450: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd 0x0a4e80007460: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd 0x0a4e80007470: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd 0x0a4e80007480: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd 0x0a4e80007490: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd =>0x0a4e800074a0: fd fd fd fd fd fd fd fd fd fd[fd]fd fd fd fd fd 0x0a4e800074b0: fd fd fd fd fd fd fd fd fd fa fa fa fa fa fa fa 0x0a4e800074c0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0a4e800074d0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0a4e800074e0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0a4e800074f0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa ```
Are you affected?
Enter the version of the package you're using.
Affected packages
0 Fixed in: 14.10.4 dotnet add package Magick.NET-Q16-AnyCPU --version 14.10.4 0 Fixed in: 14.10.4 dotnet add package Magick.NET-Q16-HDRI-AnyCPU --version 14.10.4 0 Fixed in: 14.10.4 dotnet add package Magick.NET-Q16-HDRI-OpenMP-arm64 --version 14.10.4 0 Fixed in: 14.10.4 dotnet add package Magick.NET-Q16-HDRI-arm64 --version 14.10.4 0 Fixed in: 14.10.4 dotnet add package Magick.NET-Q16-HDRI-x64 --version 14.10.4 0 Fixed in: 14.10.4 dotnet add package Magick.NET-Q16-HDRI-x86 --version 14.10.4 0 Fixed in: 14.10.4 dotnet add package Magick.NET-Q16-OpenMP-arm64 --version 14.10.4 0 Fixed in: 14.10.4 dotnet add package Magick.NET-Q16-OpenMP-x64 --version 14.10.4 0 Fixed in: 14.10.4 dotnet add package Magick.NET-Q16-OpenMP-x86 --version 14.10.4 0 Fixed in: 14.10.4 dotnet add package Magick.NET-Q16-arm64 --version 14.10.4 0 Fixed in: 14.10.4 dotnet add package Magick.NET-Q16-x64 --version 14.10.4 0 Fixed in: 14.10.4 dotnet add package Magick.NET-Q16-x86 --version 14.10.4 0 Fixed in: 14.10.4 dotnet add package Magick.NET-Q16-HDRI-OpenMP-x64 --version 14.10.4 0 Fixed in: 14.10.4 dotnet add package Magick.NET-Q8-AnyCPU --version 14.10.4 0 Fixed in: 14.10.4 dotnet add package Magick.NET-Q8-OpenMP-arm64 --version 14.10.4 0 Fixed in: 14.10.4 dotnet add package Magick.NET-Q8-OpenMP-x64 --version 14.10.4 0 Fixed in: 14.10.4 dotnet add package Magick.NET-Q8-arm64 --version 14.10.4 0 Fixed in: 14.10.4 dotnet add package Magick.NET-Q8-x64 --version 14.10.4 0 Fixed in: 14.10.4 dotnet add package Magick.NET-Q8-x86 --version 14.10.4