CVE-2015-8894: Double Free
A double free flaw was found in ImageMagick in pict.c.
Detailed stacktrace with reproducer can be found here: https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1490362
Upstream patch to the vulnerability in tga.c can be found here:
https://github.com/ImageMagick/ImageMagick/commit/4f68e9661518463fca523c9726bb5d940a2aa6d8
Other sources
Double free vulnerability in coders/tga.c in ImageMagick 7.0.0 and later allows remote attackers to cause a denial of service (application crash) via a crafted tga file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8894?
CVE-2015-8894 is classified as a moderate severity vulnerability due to the potential for exploitation in certain contexts.
How do I fix CVE-2015-8894?
To fix CVE-2015-8894, upgrade ImageMagick to a version that includes the upstream patch addressing this vulnerability.
Which versions of ImageMagick are affected by CVE-2015-8894?
CVE-2015-8894 affects specific versions of ImageMagick from 7.0.1-0 to 7.0.5-0.
What type of vulnerability is CVE-2015-8894?
CVE-2015-8894 is a double free vulnerability found in the ImageMagick library.
Can CVE-2015-8894 lead to remote code execution?
CVE-2015-8894 may potentially lead to remote code execution if exploited under certain conditions.