First published: Mon Feb 23 2015(Updated: )
A denial of service flaw (infinite loop) was found in the way ImageMagick processed certain VICAR files: <a href="http://seclists.org/oss-sec/2015/q1/608">http://seclists.org/oss-sec/2015/q1/608</a> Upstream issue, including a reproducer: <a href="http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26933">http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26933</a> A patch is not yet available as noted in <a href="show_bug.cgi?id=1195271#c2">comment 2</a> of the above-linked issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick | >=6.0<6.9.0-5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8903 has a severity rating that indicates it can lead to a denial of service due to an infinite loop when processing certain VICAR files.
To fix CVE-2015-8903, you should update ImageMagick to a version that is higher than 6.9.0-5.
CVE-2015-8903 allows attackers to cause a denial of service, making ImageMagick unresponsive when processing vulnerable files.
CVE-2015-8903 affects ImageMagick versions from 6.0 up to 6.9.0-5.
CVE-2015-8903 is classified as a denial of service vulnerability due to an infinite loop in file processing.