First published: Mon Feb 23 2015(Updated: )
A denial of service flaw (infinite loop) was found in the way ImageMagick processed certain PDB files: <a href="http://seclists.org/oss-sec/2015/q1/608">http://seclists.org/oss-sec/2015/q1/608</a> Upstream issue, including a reproducer: <a href="http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26932">http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26932</a> A patch is not yet available as noted in <a href="show_bug.cgi?id=1195269#c2">comment 2</a> of the above-linked issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | >=6.0<6.9.0-5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8902 is classified as a denial of service vulnerability due to an infinite loop that can be triggered by processing specific PDB files.
To fix CVE-2015-8902, update ImageMagick to a version above 6.9.0-5 where the issue has been resolved.
CVE-2015-8902 affects ImageMagick versions from 6.0 up to and including 6.9.0-5.
CVE-2015-8902 specifically involves PDB files that may lead to a denial of service condition when processed by ImageMagick.
CVE-2015-8902 is primarily considered a local vulnerability as it requires the exploitation of the denial of service condition on the affected server.