CVE-2018-8960: High severity ImageMagick vulnerability
Last updated 24 July 2024
Other sources
The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-26 Q16 does not properly restrict memory allocation, leading to a heap-based buffer over-read.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/imagemagickto a version that resolves this vulnerability.Fixed in 8:6.9.11.60+dfsg-1.3+deb11u4Fixed in 8:6.9.11.60+dfsg-1.3+deb11u5Fixed in 8:6.9.11.60+dfsg-1.6+deb12u2Fixed in 8:6.9.11.60+dfsg-1.6+deb12u1Fixed in 8:7.1.1.43+dfsg1-1Fixed in 8:7.1.1.47+dfsg1-1
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2018-8960.
What is the severity of CVE-2018-8960?
The severity of CVE-2018-8960 is high (8.8).
What is the affected software for CVE-2018-8960?
The affected software for CVE-2018-8960 is ImageMagick version 7.0.7-26 Q16 (up to but excluding 8:6.9.9.39+dfsg-1).
How can I fix CVE-2018-8960?
To fix CVE-2018-8960, you should update ImageMagick to version 8:6.9.9.39+dfsg-1 or later.
Where can I find more information about CVE-2018-8960?
You can find more information about CVE-2018-8960 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/103523), [ImageMagick GitHub Issue](https://github.com/ImageMagick/ImageMagick/issues/1020), and [Ubuntu Security Notice](https://usn.ubuntu.com/3681-1/).