First published: Sun Feb 25 2018(Updated: )
An issue was discovered in ImageMagick 7.0.7-22 Q16. The IsWEBPImageLossless function in coders/webp.c allows attackers to cause a denial of service (segmentation violation) via a crafted file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | =7.0.7-22-q16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7470 has a severity level classified as a denial of service vulnerability.
To fix CVE-2018-7470, update ImageMagick to a version later than 7.0.7-22.
The potential impact of CVE-2018-7470 includes causing a segmentation violation which results in a denial of service.
ImageMagick version 7.0.7-22 Q16 is specifically affected by CVE-2018-7470.
Yes, CVE-2018-7470 can be exploited remotely using crafted files.