CVE-2018-5357: Medium severity ImageMagick vulnerability
ImageMagick 7.0.7-22 Q16 has memory leaks in the ReadDCMImage function in coders/dcm.c.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/imagemagickto a version that resolves this vulnerability.Fixed in 8:6.9.11.60+dfsg-1.3+deb11u4Fixed in 8:6.9.11.60+dfsg-1.3+deb11u5Fixed in 8:6.9.11.60+dfsg-1.6+deb12u2Fixed in 8:6.9.11.60+dfsg-1.6+deb12u1Fixed in 8:7.1.1.43+dfsg1-1Fixed in 8:7.1.1.47+dfsg1-1
Event History
Frequently Asked Questions
What is CVE-2018-5357?
CVE-2018-5357 is a vulnerability in ImageMagick 7.0.7-22 Q16 that has memory leaks in the ReadDCMImage function in coders/dcm.c.
How severe is CVE-2018-5357?
The severity of CVE-2018-5357 is medium with a CVSS score of 6.5.
How can I fix CVE-2018-5357?
To fix CVE-2018-5357, you should update ImageMagick to version 8:6.9.7.4+dfsg-16ubuntu2.2 or a later version.
Where can I find more information about CVE-2018-5357?
You can find more information about CVE-2018-5357 in the following references: [GitHub](https://github.com/ImageMagick/ImageMagick/issues/941), [SecurityFocus](http://www.securityfocus.com/bid/102497), [Ubuntu Security Notice](https://usn.ubuntu.com/3681-1/).
What is the CWE ID of CVE-2018-5357?
The CWE ID of CVE-2018-5357 is 772.