The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 has an out-of-order CloseBlob call, resulting in a use-after-free via a crafted file.
- https://blogs.gentoo.org/ago/2017/07/12/graphicsmagick-use-after-free-in-closeblob-blob-c/
- https://usn.ubuntu.com/4206-1/
- https://github.com/SZU-SE/UAF-Fuzzer-TestSuite
- https://github.com/mudongliang/LinuxFlaw
- https://github.com/oneoy/cve-
- https://github.com/wcventure/UAF-Fuzzer-TestSuite