First published: Mon Aug 12 2019(Updated: )
ImageMagick is vulnerable to a denial of service, caused by a use after free vulnerability in the UnmapBlob function. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ImageMagick 6.9.10 | <42 | 42 |
redhat/ImageMagick 7.0.8 | <42 | 42 |
IBM Data Risk Manager | <=2.0.6 | |
ImageMagick | >=6.0<6.9.10-42 | |
ImageMagick | >=7.0.0-0<7.0.8-42 | |
SUSE Linux | =15.0 | |
SUSE Linux | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14980 has been classified as a medium severity vulnerability due to its potential to cause application crashes.
To fix CVE-2019-14980, update ImageMagick to version 7.0.8-42 or higher.
CVE-2019-14980 affects ImageMagick versions prior to 7.0.8-42 and certain earlier versions of ImageMagick 6.x.
Yes, CVE-2019-14980 can be exploited remotely if a victim opens a specially-crafted file.
The potential impact of CVE-2019-14980 includes denial of service due to application crashes.