REDHAT-BUG-1559892: Double Free
A flaw was found in ImageMagick 7.0.7-25 Q16. WriteEPTImage function in coders/ept.c allows remote attackers to cause a denial of service (MagickCore/memory.c double free and application crash) or possibly have unspecified other impact via a crafted file.
Reference: https://github.com/ImageMagick/ImageMagick/issues/1025
Patch: https://github.com/ImageMagick/ImageMagick/commit/6355db269e03f879c516cf9d592c72e157bc75d6
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1559892?
The severity of REDHAT-BUG-1559892 is classified as a denial of service vulnerability due to possible application crash.
How do I fix REDHAT-BUG-1559892?
To fix REDHAT-BUG-1559892, update ImageMagick to the latest version where this vulnerability is resolved.
What software is affected by REDHAT-BUG-1559892?
ImageMagick versions prior to the fix are affected by REDHAT-BUG-1559892.
Can REDHAT-BUG-1559892 be exploited remotely?
Yes, REDHAT-BUG-1559892 can be exploited remotely via a crafted file.
What impact does REDHAT-BUG-1559892 have?
The impact of REDHAT-BUG-1559892 includes denial of service and potential unspecified other impacts.