First published: Tue May 08 2018(Updated: )
A flaw was found in ImageMagick version 7.0.7-28 contains a memory leak in WriteTIFFImage in coders/tiff.c. References: <a href="https://github.com/ImageMagick/ImageMagick/issues/1053">https://github.com/ImageMagick/ImageMagick/issues/1053</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | =7.0.7-28 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =17.10 | |
Canonical Ubuntu Linux | =18.04 | |
IBM Data Risk Manager | <=2.0.6 | |
debian/imagemagick | 8:6.9.11.60+dfsg-1.3+deb11u4 8:6.9.11.60+dfsg-1.3+deb11u3 8:6.9.11.60+dfsg-1.6+deb12u2 8:6.9.11.60+dfsg-1.6+deb12u1 8:7.1.1.39+dfsg1-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10804 is a vulnerability in ImageMagick version 7.0.7-28 that allows remote attackers to cause a denial of service by exploiting a memory leak in WriteTIFFImage in coders/tiff.c.
CVE-2018-10804 has a severity rating of 6.5, classified as medium.
IBM Data Risk Manager 2.0.6, ImageMagick 7.0.7-28, and certain versions of Canonical Ubuntu Linux are affected by CVE-2018-10804.
To fix CVE-2018-10804, apply the respective patches provided by IBM, update the affected versions of ImageMagick and Canonical Ubuntu Linux, or upgrade to the fixed versions of the imagemagick package for Ubuntu or Debian.
You can find more information about CVE-2018-10804 on the official ImageMagick GitHub page, the Ubuntu Security Notice, and the CVE-2018-10804 bug report on Launchpad.