First published: Thu May 31 2018(Updated: )
In ImageMagick 7.0.7-36 Q16, the ReadMATImage function in coders/mat.c allows attackers to cause a use after free via a crafted file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick | =7.0.7-36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11624 has a medium severity rating due to its potential for exploitation through crafted MAT files.
To fix CVE-2018-11624, upgrade ImageMagick to version 7.0.8-0 or later.
ImageMagick versions prior to 7.0.8-0, including 7.0.7-36, are affected by CVE-2018-11624.
CVE-2018-11624 facilitates a use after free attack, allowing attackers to exploit the vulnerability through crafted files.
You can determine if your system is vulnerable to CVE-2018-11624 by checking your installed version of ImageMagick against the affected versions.