-
-
Notifications
You must be signed in to change notification settings - Fork 1.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Incorrect parsing Cineon causing convert
to take ridiculous time
#1472
Comments
Did you test this with a security policy applied under IM7? |
Oops, I didn't notice the policy.xml setting; this issue and #1473 no longer exist when using the default security policy. I will close them and sorry for the false alarms. BTW, is there a way to let the command line tools to find the associated configuration xml files when these tools are installed at a customized path (by setting |
@dlemstra I noticed that despite that the policy limit can avoid the issue, this does not fix the root cause: here the cineon image is small enough, however the claimed pixel is huge. I think this can be resolved by checking whether the file size can hold the pixel dimensions and quit immediately when it's not. Similar case for #1473. |
Can you post a link to your c.cin image file? We'll use it as a test case for the patch we think will resolve this problem. |
@urban-warrior c.cin is inside the attached zip file cin.zip (see above). |
Thanks for the problem report. We can reproduce it and will have a patch to fix it in GIT master branch @ https://github.com/ImageMagick/ImageMagick later today. The patch will be available in the beta releases of ImageMagick @ https://www.imagemagick.org/download/beta/ by sometime tomorrow. |
This was assigned CVE-2019-11470. |
Prerequisites
Description
Cineon image may be mistakenly parsed with incorrect pixel information, causing converting to take too much CPU resource.
Steps to Reproduce
convert c.cin /tmp/test.tmp
cin.zip
System Configuration
The text was updated successfully, but these errors were encountered: