First published: Sun Oct 21 2018(Updated: )
A flaw was found in ImageMagick 7.0.8-13 Q16. A memory leak in the function WriteMSLImage of coders/msl.c. References: <a href="https://github.com/ImageMagick/ImageMagick/issues/1360">https://github.com/ImageMagick/ImageMagick/issues/1360</a> Upstream Patch: <a href="https://github.com/ImageMagick/ImageMagick/commit/c9c4ef4e7ca83d8a00effd16723f37946e89fbad">https://github.com/ImageMagick/ImageMagick/commit/c9c4ef4e7ca83d8a00effd16723f37946e89fbad</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Graphicsmagick Graphicsmagick | <1.3.31 | |
ImageMagick ImageMagick | =7.0.8-13-q16 | |
openSUSE Leap | =15.0 | |
redhat/ImageMagick 7.0.8 | <13 | 13 |
redhat/ImageMagick 6.9.10 | <13 | 13 |
IBM Data Risk Manager | <=2.0.6 | |
debian/graphicsmagick | 1.4+really1.3.36+hg16481-2+deb11u1 1.4+really1.3.40-4 1.4+really1.3.45-1 | |
debian/imagemagick | 8:6.9.11.60+dfsg-1.3+deb11u4 8:6.9.11.60+dfsg-1.3+deb11u3 8:6.9.11.60+dfsg-1.6+deb12u2 8:6.9.11.60+dfsg-1.6+deb12u1 8:6.9.13.12+dfsg1-1 8:7.1.1.39+dfsg1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-18544.
The title of this vulnerability is 'There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16 and…'
The description of this vulnerability is that ImageMagick is vulnerable to a denial of service, caused by a memory leak in the WriteMSLImage function in coders/msl.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
The severity of CVE-2018-18544 is medium with a CVSS score of 6.5.
The affected software includes ImageMagick 7.0.8-13 Q16, IBM Data Risk Manager up to version 2.0.6, Graphicsmagick up to version 1.3.31, and openSUSE Leap 15.0.