CVE-2018-9018: Divide by Zero
In GraphicsMagick 1.3.28, there is a divide-by-zero in the ReadMNGImage function of coders/png.c. Remote attackers could leverage this vulnerability to cause a crash and denial of service via a crafted mng file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/graphicsmagickto a version that resolves this vulnerability.Fixed in 1.4+really1.3.36+hg16481-2+deb11u1Fixed in 1.4+really1.3.40-4Fixed in 1.4+really1.3.45+hg17689-1 - Compensating control
Protect affected GraphicsMagick deployments from crafted .mng files by blocking or filtering inbound MNG content at a network layer (e.g., WAF/ACL) to prevent remote attackers from triggering the ReadMNGImage divide-by-zero crash/denial of service.
Event History
Frequently Asked Questions
What is CVE-2018-9018?
CVE-2018-9018 is a vulnerability found in GraphicsMagick 1.3.28 that allows remote attackers to cause a crash and denial of service by exploiting a divide-by-zero in the ReadMNGImage function of coders/png.c.
How severe is CVE-2018-9018?
CVE-2018-9018 has a severity rating of 6.5, which is considered medium.
What software versions are affected by CVE-2018-9018?
The affected software versions include GraphicsMagick 1.3.28.1.3.28-2, GraphicsMagick 1.3.18-1ubuntu3.1+, GraphicsMagick 1.3.29, GraphicsMagick 1.3.23-1ubuntu0.6+, GraphicsMagick 1.4+really1.3.35-1~deb10u2, GraphicsMagick 1.4+really1.3.35-1~deb10u3, GraphicsMagick 1.4+really1.3.36+hg16481-2+deb11u1, GraphicsMagick 1.4+really1.3.40-4, and GraphicsMagick 1.4+really1.3.42-1.
How do I fix CVE-2018-9018?
To fix CVE-2018-9018, upgrade to GraphicsMagick version 1.3.28-2 or apply the available security patches for the affected software versions.
Where can I find more information about CVE-2018-9018?
You can find more information about CVE-2018-9018 at the following references: [1] http://www.securityfocus.com/bid/103526 [2] https://lists.debian.org/debian-lts-announce/2018/03/msg00025.html [3] https://lists.debian.org/debian-lts-announce/2018/08/msg00002.html