First published: Tue Feb 13 2018(Updated: )
A stack-based buffer over-read in the ComputeResizeImage function in the MagickCore/accelerate.c file of ImageMagick 7.0.7-22 allows a remote attacker to cause a denial of service (application crash) via a maliciously crafted pict file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick | =7.0.7-22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6930 is categorized as a high severity vulnerability due to the potential for denial of service and application crash.
To fix CVE-2018-6930, upgrade ImageMagick to a version later than 7.0.7-22 where this vulnerability has been addressed.
CVE-2018-6930 is a stack-based buffer over-read vulnerability.
CVE-2018-6930 affects users of ImageMagick version 7.0.7-22 or earlier.
The impact of CVE-2018-6930 is that a remote attacker can cause a denial of service by exploiting the vulnerability, leading to application crashes.