First published: Mon Feb 23 2015(Updated: )
A denial of service flaw (infinite loop) was found in the way ImageMagick processed certain MIFF files: <a href="http://seclists.org/oss-sec/2015/q1/608">http://seclists.org/oss-sec/2015/q1/608</a> Upstream issue, including a reproducer: <a href="http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26931">http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26931</a> A patch is not yet available as noted in <a href="show_bug.cgi?id=1195265#c2">comment 2</a> of the above-linked issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick | >=6.0<6.9.0-5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8901 has a high severity rating due to its potential to cause a denial of service by entering an infinite loop.
To fix CVE-2015-8901, update ImageMagick to a version later than 6.9.0-5.
The impact of CVE-2015-8901 is that it can lead to system unavailability by freezing the application processing MIFF files.
CVE-2015-8901 affects ImageMagick versions from 6.0 up to and including 6.9.0-5.
Yes, CVE-2015-8901 can be exploited remotely if an attacker can upload or send a specially crafted MIFF file.