DescriptionThe ReadGROUP4Image function in coders/tiff.c in ImageMagick does not check the return value of the fwrite function, which allows remote attackers to cause a denial of service (application crash) via a crafted file.
Debian Bugs849439

imagemagick (PTS)wheezy8:
wheezy (security)8:
jessie (security)8:
stretch (security), stretch8:
buster, sid8:

CVE is for the fwrite issue in ReadGROUP4Image. This was
specifically noted at the beginning of issues/196, but not fixed in
either of these commits 933e96f01a8c889c7bf5ffd30020e86a02a046e7 nor
4e914bbe371433f0590cefdf3bd5f3a5710069f9 upstream. It is not the same
as the fputc issue in ReadGROUP4Image.

