CVE-2018-7443: Medium severity ImageMagick ImageMagick vulnerability
Last updated 24 July 2024
Other sources
The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-23 Q16 does not properly validate the amount of image data in a file, which allows remote attackers to cause a denial of service (memory allocation failure in the AcquireMagickMemory function in MagickCore/memory.c).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/imagemagickto a version that resolves this vulnerability.Fixed in 8:6.9.11.60+dfsg-1.3+deb11u4Fixed in 8:6.9.11.60+dfsg-1.3+deb11u5Fixed in 8:6.9.11.60+dfsg-1.6+deb12u2Fixed in 8:6.9.11.60+dfsg-1.6+deb12u1Fixed in 8:7.1.1.43+dfsg1-1Fixed in 8:7.1.1.47+dfsg1-1 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.0.7-23 Q16
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-7443.
What is the severity of CVE-2018-7443?
The severity of CVE-2018-7443 is medium with a severity value of 6.5.
How does the vulnerability CVE-2018-7443 impact ImageMagick?
The vulnerability CVE-2018-7443 allows remote attackers to cause a denial of service in ImageMagick by exploiting a memory allocation failure.
How can I fix the vulnerability CVE-2018-7443 in ImageMagick?
To fix the vulnerability CVE-2018-7443 in ImageMagick, you need to update to version 8:6.9.9.39+dfsg-1 or later.
Are there any references related to CVE-2018-7443?
Yes, you can find references related to CVE-2018-7443 at the following URLs: [Reference 1](https://github.com/ImageMagick/ImageMagick/issues/999), [Reference 2](https://lists.debian.org/debian-lts-announce/2018/02/msg00028.html), [Reference 3](https://usn.ubuntu.com/3681-1/).