Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CABfY0L0q8fJjyyHKpZumOesDm72yNwebVQxa21TStFhAO+3atw@mail.gmail.com>
Date: Thu, 26 Feb 2015 14:50:14 -0600
From: Jodie Cunningham <jodie.cunningham@...il.com>
To: oss-security@...ts.openwall.com
Cc: cve-assign@...re.org
Subject: Re: Requesting CVE for ImageMagick DoS

Adding cve-assign to cc

-Jodie
Hi,

I wanted to share four DoS bugs I found via fuzzing with AFL in
ImageMagick, as the maintainer has since corrected them. I'd like to
request the appropriate CVE(s) to cover these DoS bugs:

Date, File ID, ShortDescription, Bug report URL:
1/24/2015 3c1c3e63 HDR file DoS, CPU
 http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26929

1/25/2015 d595506c MIFF file DoS, CPU
 http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26931

1/25/2015 c8ad6aba PDB file DoS, CPU
http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26932

1/25/2015 783d8806 VICAR file DoS, CPU
http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26933


Regards,
-Jodie Cunningham

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.