CVE-2023-5349: Draw while calling getdrawinfo()
A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick. This issue can lead to a denial of service (DOS) by memory exhaustion.
Other sources
A memory leak was found in ruby-magick an interface between Ruby and ImageMagick, that could lead to a Deny of Service (DOS) by memory exhaustion.
References:
https://github.com/rmagick/rmagick/issues/1401 https://github.com/rmagick/rmagick/pull/1406
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-5349?
CVE-2023-5349 is a memory leak flaw in ruby-magick, an interface between Ruby and ImageMagick.
What is the severity of CVE-2023-5349?
CVE-2023-5349 has a severity level of medium (5.3).
How does CVE-2023-5349 affect software?
CVE-2023-5349 can lead to a denial of service (DOS) by memory exhaustion.
How can I fix CVE-2023-5349?
To fix CVE-2023-5349, update ruby-magick to the latest version available.
Where can I find more information about CVE-2023-5349?
More information about CVE-2023-5349 can be found at the following references: - [Red Hat Security Advisory](https://access.redhat.com/security/cve/CVE-2023-5349) - [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2247064) - [RMagick GitHub Issue](https://github.com/rmagick/rmagick/issues/1401)