Page 1 of 1

CVE-2015-8126: Multiple buffer overflows in libpng

Posted: 2015-11-16T05:40:35-07:00
by spender
Is CVE-2015-8126 a problem for ImageMagick? There are probably quite a number of users with ImageMagick running on servers, so if there is a problem, it probably needs looking at fairly quickly.

/spender

Re: CVE-2015-8126: Multiple buffer overflows in libpng

Posted: 2015-11-16T17:58:08-07:00
by glennrp
ImageMagick is not vulnerable to CVE-2015-8126. In fact I do not know of any libpng application that is actually vulnerable, although it would be possible to write one.