First published: Tue Jan 09 2018(Updated: )
A flaw was found on ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability in the function ReadDDSInfo in coders/dds.c file, which allows attackers to cause a denial of service. [UPSTREAM BUG] <a href="https://github.com/ImageMagick/ImageMagick/issues/867">https://github.com/ImageMagick/ImageMagick/issues/867</a> [UPSTREAM PATCH] <a href="https://github.com/ImageMagick/ImageMagick/commit/e5dae180b9236bccd73ce93bfce81e99232a8533">https://github.com/ImageMagick/ImageMagick/commit/e5dae180b9236bccd73ce93bfce81e99232a8533</a>
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1532845 is classified as a denial of service vulnerability due to CPU exhaustion.
To fix REDHAT-BUG-1532845, update ImageMagick to a version that addresses the CPU exhaustion vulnerability.
ImageMagick version 7.0.7-12 Q16 is affected by REDHAT-BUG-1532845.
REDHAT-BUG-1532845 is a CPU exhaustion vulnerability that can lead to denial of service.
The vulnerability in REDHAT-BUG-1532845 is found in the function ReadDDSInfo within the coders/dds.c file.